Avantec AG
Zug
Managed Threat Hunting – AVANTEC
- 08 August 2026
- 100%
- Permanent position
- Zug
Job summary
Explore the world of Threat Hunting services and strategies.
Tasks
- Understand how Crowdstrike's Falcon OverWatch operates.
- Learn the role of Threat Intelligence in effective hunting.
- Discover the benefits of Managed Threat Hunting for businesses.
Skills
- No prior experience needed, just a keen interest in cybersecurity.
- Analytical thinking and problem-solving abilities.
- Familiarity with cybersecurity tools and concepts.
Is this helpful?
About the job
Threat Hunting has already been mentioned in various Tec-Bite blog articles, either as a do-it-yourself approach or as a service. In this article, I want to try to provide a behind-the-scenes look and show how such a Threat Hunting service works and what you get offered. Since I am well acquainted with Crowdstrike OverWatch's offering and know that they deliver on their promises, I want to use the service as an example in this article. What is Threat Hunting? Threat Hunting means searching for potentially existing threats. A Threat Hunter operates on the premise that a Threat Actor is already present in the network and now wants to track them down. In contrast, a Next-Gen AV or prevention solution tries to nip an attack in the bud. Unfortunately, it is wishful thinking to believe that everything can be blocked with an antivirus solution. Keyword: (re)cognition of the unknown. Threat Hunting as a Service Managed Threat Hunting is now available from various providers, whether pure service providers or direct services from manufacturers. Crowdstrike also offers a first-class Threat Hunting service with "Falcon OverWatch," based on their EDR solution. Unlike other manufacturers who have jumped on the EDR/MDR bandwagon, Threat Intelligence has always been a key pillar of Crowdstrike. This, in turn, directly influences the quality of Managed Threat Hunting because Threat Hunting cannot work without good Threat Intelligence. Just as Tom Selleck, aka Thomas Magnum, would never have caught a crook without a good lead. A series I warmly recommend, by the way. Crowdstrike publishes Threat Hunting reports several times a year, quarterly, as well as an annual review. The latest report has just been released. Interested parties can obtain the report here. Some key figures from last year (1 July 2021 – 30 June 2022): 77,000 potential attacks were detected and stopped by OverWatch. Over 1 million malicious events were prevented. Around 71% of threats were file-less or malware-free attacks. Measured by the number of incidents, this is a 600% growth since 2019. OverWatch – Service In conversations with customers, I often sense some uncertainty when it comes to this "ominous" OverWatch service. One reason is usually that you cannot really see the service, let alone test it yourself in a proof of value. Or, at best, you simply never had anything to do with OverWatch, simply because there were no incidents. So why should I spend a lot of money on something I see no benefit from? It is perhaps a bit like insurance; you usually only pay in without getting anything in return, but in an emergency, you are glad to have it. Anyone who has ever set up or wanted to set up such a service knows how difficult it is to find suitable staff. Crowdstrike's Threat Hunters are all specialists with many years of (technical) experience, often with a background in intelligence services. The analysts' expertise is also coordinated within the teams to ensure the broadest possible coverage of various attack vectors. To ensure uninterrupted 24/7 service, shift work is, of course, employed. The Threat Hunters then do nothing all day but search for potential threats. They work directly in the Falcon Investigate app, the same interface available to Crowdstrike EDR customers. Using appropriate search queries, they look for suspicious occurrences. The difficulty here lies less in operating the app and more in knowing what to look for. Keyword: Threat Intelligence. In addition to human analysts, OverWatch also uses various self-developed tools and scripts that pre-filter the masses of new events and create corresponding leads from suspicious occurrences. And we are really talking about immense volumes of events! The latest figures from Crowdstrike from August mention 135 million IOA (Indicator of Attack) decisions per minute and over 1 trillion events per day. Of course, measured across all Crowdstrike customers. These suspicious leads are further checked by other tools, and if suspicion hardens, an investigation is launched. These investigations are then carried out by human analysts, and in serious cases, the customer is informed, including a recommendation on how to handle the incident. The analysts are thus almost like external employees, a useful addition to an existing security team. The following graphic illustrates the process better. The upper grey part represents the existing security solutions. Using behavioural analysis and machine learning, events are analysed, and an alert is created if there is suspicion. The lower red part stands for the OverWatch service. Parallel to the existing workflow, the data is additionally analysed separately, resulting in leads if there is suspicion. These are then examined more closely by human analysts. Threat Hunting is thus a human detection component. Crowdstrike OverWatch Workflow OverWatch – Threat Intelligence With over a trillion events per day, the comparison to the proverbial search for a needle in a haystack is obvious. It is all the more important to use good and reliable Threat Intelligence or, in the haystack, a very strong magnet. Threat Intel definition from Merriam Webster: "information concerning an enemy or possible enemy or an area." It is about knowing as much as possible about potential attackers; which attackers affect my industry, what tools they use, how they proceed, where the attacks come from, etc. The current OverWatch Report 2022 includes an interesting graphic on this: Crowdstrike OverWatch Threat Hunting Report 2022 As mentioned at the beginning, Threat Intelligence has been a core business of Crowdstrike since its founding. Various technical and non-technical teams serve as sources, for example, searching the dark web for upcoming attacks on customer XY, analysing leaked password dumps, or providing strategic/geopolitical information on current events. Experiences and findings from incident response deployments also flow into the Threat Intel. But not only the OverWatch service benefits from the Threat Intel; for example, the vulnerability module Spotlight also uses this information to prioritise security vulnerabilities. Conclusion Many companies already use EDR solutions or want to supplement or even replace an existing antivirus product with EDR. That is fine but does not bring many advantages per se. An EDR collects mountains of data, but it is useless if I do not evaluate it. I can evaluate this data either with advanced tools like vulnerability management or IT hygiene or by conducting Threat Hunting. And since most companies, especially in the SME sector, do not have their own specialists for this, a corresponding service is naturally an option. By the way, a small but fine IT security specialist from Switzerland now also offers a Managed Detection & Response service. The article Managed Threat Hunting – what does it bring? first appeared on Tec-Bite.