Threat Hunting & Compromise Assessment
Suspect an intruder is already inside? Our threat hunting finds the attacker your alerts missed, with evidence and a clear verdict. Start now.
If you suspect an intruder is already inside your network right now, threat hunting is how you get a straight answer instead of a hunch. Our European team goes looking for the attacker your alerts never flagged: quiet persistence, credentials being reused, and the account that signs in at 3am from a country you have never sold to.
What threat hunting actually looks for
A vulnerability scanner tells you what could be exploited. Threat hunting answers the question that keeps you awake: is someone already here, and what have they touched? We start from an assumption of compromise and work backwards from evidence. That means hunting through logs, memory, and endpoints for the faint traces a patient attacker leaves, rather than waiting for a dashboard to turn red. In the compromises we clean up, the intruder had usually been resident for weeks before anyone noticed anything at all.
The hypotheses we hunt against
Good hunting is not random log-staring. We build specific, testable hypotheses drawn from real attacker behaviour and test each one against your telemetry. If a hypothesis holds, we pull the thread until we understand the full picture.
Where the evidence lives
Attackers touch more than one place, so we correlate across sources instead of trusting a single feed. Endpoint process trees, authentication logs, EDR telemetry, firewall and proxy records, cloud audit trails, and volatile memory each hold a different fragment of the story. A login that looks fine in one log often looks alarming once you line it up against the process that spawned from it.
Proactive hunting versus a live compromise assessment
People arrive here for two different reasons, and the work differs accordingly.
Proactive threat hunting
Nothing has obviously gone wrong, but you want certainty before an audit, a funding round, or a board question you cannot answer with a shrug. Here the value is a documented, evidence-based verdict: either we find nothing and you can say so with confidence, or we surface something quietly that would otherwise have become a breach in a month.
Compromise assessment under suspicion
Something feels wrong. A supplier warned you, an antivirus alert fired and vanished, money moved, or a staff member reported strange behaviour. This is faster and more focused. We confirm or rule out an active intrusion, and if one exists we move straight into containment and full incident response without losing a day to handovers.
Managed and one-off engagements
Some clients want a single deep sweep. Others want recurring managed threat hunting so a fresh set of eyes examines their estate every quarter, tuned to the attacks that actually target their sector. We size the cyber threat hunting service to your risk, not to a fixed product tier.
Our response process
Whether you engage us proactively or mid-scare, the work follows the same disciplined path so nothing is skipped under pressure.
Triage
We start with a short call to understand your environment, what prompted the concern, and where your most valuable data sits. Within hours we are ingesting telemetry and forming the first hunting hypotheses. If there is an obvious active threat, triage compresses into minutes and we escalate at once.
Contain
If we confirm an intruder, containment comes before cleanup. We isolate affected hosts, cut attacker access, revoke stolen tokens and sessions, and reset the credentials in play, all while preserving evidence rather than trampling it. Rushing to wipe a machine destroys the very proof you need later.
Eradicate
We remove every persistence mechanism we have mapped, close the entry point, and verify the attacker cannot simply walk back in through a second door they left open. One backdoor is never the whole story, so we keep hunting until the estate is quiet.
Recover
We help you return clean systems to service in a sensible order, confirm that monitoring now sees what it previously missed, and watch for any sign the intruder tries to come back.
Harden
Finally we turn findings into fixes: detection rules for the techniques we saw, tighter logging where you were blind, and a short list of changes that would have stopped this. The point of a hunt is not just to find the attacker but to make the next one visible on day one.
Want this tested on your own systems?
Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.
How they got in, and how we prove it
Every client asks the same first question: how did this happen? We treat that as core to the work, not an afterthought.
Root-cause forensics
We reconstruct the timeline from initial access through to the latest activity, so you can see the phishing email, the exposed service, or the reused password that opened the door. Understanding the root cause is the only way to be sure eradication actually holds.
Evidence handling
We work to a defensible standard. Findings are backed by hashes, timestamps and preserved artefacts, handled so they remain usable if the matter ever reaches insurers, regulators or a court. If you may need a formal forensic report, tell us at the start and we will collect accordingly.
What you get
You get a plain verdict first, then the depth behind it. No dashboard access we quietly bill for, no vague reassurance.
Prevention after the hunt
A hunt that ends with a report and no change is a waste of your money. We close the loop.
Detection engineering
We write and tune the alerts that would have caught this attacker earlier, so the same technique lights up next time instead of slipping past. Where you lacked the logs to detect it at all, we tell you exactly which sources to turn on.
Reducing the attack surface
Most intrusions rely on something avoidable: an exposed remote-access service, a shared local admin password, or a mailbox with no multi-factor authentication. We give you the short list that matters most, ranked by how much risk each item removes. None of it is theoretical: every recommendation traces back to something we actually saw or could have seen in your own telemetry, so your team can prioritise with confidence instead of guessing.
Timelines and common triggers
Speed matters most when something is actively wrong, so here is what the clock usually looks like.
What to expect on the calendar
An emergency compromise assessment gets a same-day response and a first read on whether an intrusion is live, often within the first day of telemetry. A full estate hunt typically runs three to ten working days depending on how many endpoints and identities are in scope and how clean your logging is. We give you interim findings as we go rather than making you wait for a final document, because if we confirm an active attacker on day two you need to know on day two.
What usually brings people to a hunt
The triggers repeat. A bank or payment processor flags fraudulent transactions tied to your systems. An employee reports that colleagues received messages they never sent. A backup job suddenly balloons in size because data is being staged. A supplier tells you their network was breached and yours connects to it. Sometimes there is no single event, only a nagging sense that the last penetration test found too much and nobody ever checked whether it was already being abused. Any of these is a good reason to look properly rather than hope.
The cost of waiting
Dwell time works against you. The longer an intruder sits undetected, the more credentials they collect, the deeper their persistence goes, and the harder eradication becomes. Hunting early, while the footprint is small, is far cheaper than recovering from the full breach it would have grown into.
Pricing
Threat hunting is scoped by the size of your estate and how fast you need answers. A focused compromise assessment on a small environment is very different from an ongoing managed hunt across hundreds of endpoints, so we quote after a short call rather than pretend one number fits all.
| Package | What’s included | Response time | Price |
|---|---|---|---|
| Emergency compromise assessment | Rapid confirmation of an active intrusion on a single environment, immediate triage and containment guidance | On call, same day | from €900 |
| Hourly hunting | Focused hunting and forensics led by a senior analyst, billed by the hour for smaller or well-defined scopes | Starts within hours | from €180/hr |
| Full compromise assessment | Whole-estate hunt across endpoints, identity, cloud and network, with verdict and remediation plan | 3–10 working days | scoped after a call |
| Managed threat hunting | Recurring hunts on a retainer, tuned to your sector, with agreed response SLA and discounted hourly rate | Ongoing | from €800/month |
| Large or complex estate | Multiple sites, subsidiaries or a hybrid-cloud footprint, scoped to your needs | On scoping | custom |
Every engagement is a fixed price agreed after a free scoping call, and a retest is included once you fix. Start emergency response
FAQ
How much does threat hunting cost?
Can you tell me how they got in?
What if you find nothing?
How is this different from my antivirus or EDR?
Will hunting disrupt our operations?
Do you offer ongoing managed threat hunting?
Is the engagement confidential?
Can this support a compliance or audit requirement?
Related services
Security and IT leaders who suspect a breach, teams preparing for an audit or acquisition, and organisations that want independent confirmation their environment is genuinely clean before something forces the question.
Security you can prove
The same standard on every engagement, big or small.
Evidence, not opinions
Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".
Humans over scanners
Certified engineers find the logic flaws and chained attacks automated tools walk straight past.
Fixed price, free retest
You know the cost up front, and verifying the fix is part of the deal — not a second invoice.
Ready to lock this down?
Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.
Tell us what you're running
Scoping is free. We reply within one business day, and under 30 minutes for active incidents.