Skip to content

SERVICE

Threat hunting

Three simultaneous paths: hypotheses from your sector's actor TTPs, indicators from our own intelligence and the FIRST network, and anomaly analytics over your baseline. The agent sweeps 90 days of history; the human hunter formulates, interprets and confirms.

MITRE ATT&CK as the mapRetroactive huntingL3 hunter
AT A GLANCE
Frequency Weekly hypotheses + monthly campaign
Data window 90 days of hot telemetry
Who hunts AI agents + L3 analyst
Result New detections, not just findings
HOW WE WORK

The methodology, step by step

01

Threat model

Hypotheses prioritized by the groups attacking your sector: "if an adversary did X here, what trace would it leave?"

02

Agentic sweep

✦ AI AGENT

The agent sweeps 90 days of telemetry in minutes, enriches each candidate and dismisses the explainable with logged reasoning.

03

Human validation

The L3 hunter reconstructs the activity and separates real findings from legitimate behavior.

04

Containment or closure

Confirmed findings go to response with a runbook; risk that isn't an incident is documented and accepted in writing.

05

New detection

✦ AI AGENT

Every finding becomes a deployed rule: next time it will be an alert, not a hunt.

SERVICE TIERS

Pick the tier that answers your question

The price is fixed in writing after a 30-minute scoping and does not change during the contract.

Hunting within the CROC

FREQUENCY
Weekly, over alerts
DATA SCOPE
CROC telemetry
HUNTER
Shared
NEW RULES
As they emerge
RECOMMENDED

Directed campaign

FREQUENCY
2–4 week campaign
DATA SCOPE
Agreed source per campaign
HUNTER
Assigned to the campaign
NEW RULES
Included at closure

Continuous + retroactive

FREQUENCY
Continuous, all year
DATA SCOPE
Full telemetry + 90 days back
HUNTER
Named, knows your environment
NEW RULES
Managed detection backlog

Thirty minutes and we tell you frankly what you need.

Sometimes the answer is "you don't need us yet." We prefer that to selling you something you won't use.