Skip to content

Security2 publishers2 min readPublished Updated

Threat hunters put data quality ahead of staffing for the first time in five SANS surveys

Data quality or quantity now leads the barrier list in the SANS threat hunting survey, the first time in five years it has outranked staffing, and the report says collection has outrun normalization.

The Watch · Security desk

Illustration accompanying Threat hunters put data quality ahead of staffing for the first time in five SANS surveys

What happened

  • Most respondents see nation-state actors living off the land, and the technique tops the list for organized crime and runs a close second for ransomware gangs.
  • A third of respondents named cloud infrastructure the hardest environment to hunt in, ahead of every other environment, a share that has eased only a little since last year.
  • Only 37% of hunting programs follow a formally defined methodology, and ad hoc hunting is now slightly more common.
  • Just 40% of programs formally measure whether their hunts work, down from 64% in 2024.
  • A third of respondents plan to add AI or machine learning to their hunting tools, down from 48% who said so in 2025.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint Behavioral hunts are what catch an intruder using admin tools, and each one fails wherever the team lacks the telemetry, most often in cloud and identity systems.
  • exposure Living off the land leads or runs second for every actor class respondents track, so gaps in cloud and identity logs weaken hunts across the whole caseload.
  • cost Raising the ceiling means paying for log collection at scale, longer retention and log integrity controls, the items Wake lists for defenders.
  • constraint Programs that stopped measuring have little evidence of results to bring to the budget meeting where that logging spend gets decided.

A hunt keyed to known bad hashes or IP addresses will not catch an operator using the same tools as the IT department [15]. It has to target behavior, such as a legitimate tool doing something it should not or data leaving by an unusual route [16]. Those checks depend on a picture of normal activity [17]. According to the survey write-up, a picture built from patchy or inconsistent logs makes the hunt flag noise while the intrusion slips by [17].

Taz Wake, a SANS instructor, has watched attackers work to cover their tracks. That raises the cost of every gap in collection [18]. "Defenders need to consider evidence retention windows, log integrity risks, and the challenge of data collection at scale," Wake wrote in commentary for the survey [10].

Teams that already have working playbooks describe the logs as their ceiling [2]. Staffing is the other limit in the numbers. Josh Lemon, the survey's author, points to it as the likely reason for the drift toward ad hoc hunting [5]. A short-handed team runs whatever hunt its free analyst can handle that week [6]. The published write-up does not report the sample size or what share of respondents named staffing or skills as their top barrier. On that record, it cannot show whether telemetry limits hunting more than people do.

A hunt that lives in one analyst's head leaves the company with that analyst [19]. Published frameworks such as PEAK and TaHiTI give teams a repeatable structure without starting from scratch [14].

Reported results fell as measurement did. Just 11% of respondents said hunting improved their security by 50% or more over the past year, against 47% in 2022, a drop of 36 points [8][2]. The survey cannot tell whether hunting is delivering less, whether respondents are grading themselves harder, or whether teams that stopped measuring stopped noticing results [12]. Lemon leans toward the last [9]. "You tend to find less when you are not looking for it," he said [9].

The fall in AI plans could mean teams have moved from planning to implementation, or that they have looked harder at what the tools deliver day to day, according to the write-up [20]. Early free-text answers describe agentic hunting frameworks that keep analysts making the calls [13].

What to watch

  • Whether the full SANS report gives the sample size and the share naming staffing or skills as the top barrier, which would test data against people directly.
  • Whether cloud's share as the hardest environment to hunt in falls in the next survey as more systems move there.
  • Whether the free-text accounts of agentic hunting frameworks show up as measured results in next year's numbers.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories