Security1 publisher3 min readPublished
72.7% of SANS hunters who caught nation-state intruders saw them abuse native admin tools
SANS's 2026 hunting survey found 72.7% of hunters who caught nation-state actors saw them living off the land, against 63.4% for ransomware crews. Hunters rank data quality as their top barrier, so detecting misused admin tools starts with the telemetry those hunts depend on.
The Watch · Security desk

What happened
- Targeted exfiltration came close behind: 64.8% of those who found nation-state actors saw it, as did 65.4% of those who found ransomware groups, where it edged past living off the land.
- Evidence deletion was seen by 46.6% of hunters who found nation-state actors, 39.5% of those who found ransomware groups and 30.6% of those who found organized crime.
- Nearly half of respondents run three to ten hunts a month, and 31% say a typical hunt takes nine to 24 hours.
- Data quality or quantity was the top barrier to hunting at 50.2%, ahead of skilled staff at 45% and budget constraints at 42%.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- decision Teams weighing defenses tuned for AI-speed attacks against behavioral detection now have survey evidence that most caught intrusions run on native tools, which SANS says signatures will not find.
- constraint Behavioral hunts depend on correlating process, account and baseline telemetry, so weak data quality, the most-cited barrier, limits them before staff numbers do.
- exposure Responders reaching a ransomware incident after encryption inherit a thinner record, because crews now invest in anti-forensics earlier and clear event logs.
The 72.7% is a share of respondents, counted only among hunters who uncovered a nation-state actor [2]. It describes the intrusions that got caught. Nation-state operators led ransomware crews on native-tool use by 9.3 percentage points [1]. SANS calls living off the land, meaning legitimate admin tools used to blend into normal system activity, the "default adversary posture" across threat profiles [1]. Intel 471, which published the findings, sets them against this year's narrative of fast, autonomous AI-driven attacks. It says the results suggest attackers are prioritizing access and operational security, and that hunter interest in AI-assisted hunting may be cooling [19].
Intel 471's own hunt data for Q2 2026 points the same way. Exfiltration Over C2 Channel (T1041) was the most-observed MITRE ATT&CK technique, with living-off-the-land execution, valid account and credential abuse, and supply chain compromise also dominant [8]. Its hunters described a preference for "high-return, low-noise tradecraft, leveraging native tools and legitimate credentials to maintain access while avoiding the detection risks inherent in overly complex or novel exploit chains" [9].
Finding that tradecraft is slow work. SANS wrote that these techniques will not be found by signature matching. Hunts for them "start with questions about what legitimate tools should not be doing, where data should not be going, and what system activity is statistically unusual" [11]. Intel 471 says the behaviors look benign in isolation and can be surfaced by correlating telemetry: unusual process lineages, atypical account interactions, sequences that break from operational baselines [10]. Behavioral hunts take more time [12].
SANS spelled out the load: "A program running six or more hunts per month, each lasting two to three days, is asking a lot of people who almost certainly have other responsibilities alongside their hunting work" [14]. Six hunts at that length is 12 to 18 working days of hunting a month [2].
The evidence-deletion figures cut into what responders inherit. SANS reads the ransomware and organized crime numbers as financially motivated groups investing in anti-forensics earlier in the intrusion, buying time before a ransom demand [5]. Intel 471 updated its "Wevtutil Cleared Log" hunt package after Settra, a ransomware and data extortion newcomer, was seen clearing Windows Event Logs after encrypting files [6]. Log clearing is often paired with shadow-copy deletion to block restoration [7].
The UK's National Cyber Security Centre has described a structural asymmetry. Attackers mostly face technical obstacles; defenders face organizational ones, needing buy-in to secure budgets, patch systems and change configurations [16]. Respondents also said hunting works in pockets and that outcomes often depend on the analyst running the hunt [18].
On this evidence, money for detecting misused admin tools and stolen credentials matches what hunters are finding [2][8]. The findings as published do not include a count of AI-driven intrusions, so they cannot say whether fast attacks are rare or less often caught. Speed still matters on the defender side: SANS wrote that adversaries are "not waiting for monthly hunt cycles to find them" [15]. Behavioral hunts run on correlated telemetry, and data quality or quantity is the barrier respondents cite most [10][17].
What to watch
- The full SANS figures on AI-assisted hunting, which Intel 471 says show hunter interest may be cooling.
- Whether more ransomware newcomers follow Settra in clearing Windows Event Logs after encryption, as tracked in Intel 471 hunt package updates.
- Any SANS or NCSC data counting AI-driven intrusions, which would allow a direct comparison between the stealth and speed readings.