# Threat Hunting | Novacoast

> Continuous threat hunting via a centralized watch-list pushed to your SIEM and EDR by API, plus hygiene hunts. Findings become permanent detections.

Canonical: https://novacoast.com/threat-hunting/

# A hunt that keeps working after the hunt ends.

A centralized hunt watch-list pushed to every environment by API, plus hygiene hunts for the misconfigurations attackers actually use. Findings become detections and stay.

[Request a scoping call](https://novacoast.com/contact-us/) [How the SOC works](https://novacoast.com/managed-security-services/#model)

how the thesis applies here

01 Our researchers build the watch-list from what we see across environments and what the feeds say.

02 It's pushed to your SIEM and EDR by API, so the hunt runs continuously, not once a quarter.

03 A hit is correlated and enriched like any alert, and reaches a named engineer if it matters.

04 What we find becomes a permanent detection in your platform.

## The specifics.

continuous

### Watch-list by API

Indicators and behaviours pushed to every environment we operate, updated as our research updates.

hygiene

### Hunts for the boring things

Stale admin accounts, open shares, unpatched edge devices, the things that turn a phishing email into a breach.

research

### Our own intelligence

Curated, deduplicated, and pushed wherever it's needed, not only into the SIEM.

outcome

### Findings become detections

A hunt that produces a report is a hunt that ends. Ours produce rules that stay.

people

### Hunters on the floor

The same engineers who own your escalations. They know what normal looks like in your environment.

scope

### Endpoint, identity, network, cloud

Wherever the data is.

## Operated in your tenant.

Runs on whatever SIEM and EDR you own. Requires nothing new.

## What buyers ask first.

Is this included with the SOC?

Yes. Threat hunting is part of the co-managed SOC. It can also run as a standalone engagement.

How often do you hunt?

Continuously, by API. The watch-list is always live. Targeted hunts run when our research or your situation warrants one.

What do we get?

Detections in your platform, first. A written record of what was found, second.

## Ask us what we would hunt for first in your environment.

We'll tell you, on the call.

[Request a scoping call](https://novacoast.com/contact-us/) 30 minutes, senior engineer, no deck.
