Skip to main content
BilgeQor

Threat Hunting Engagement

In Lithuania, the NIS2-oriented cyber resilience expectations context gives a bounded foundation for a hypothesis-led Threat Hunting Engagement based on a resilience review brief, authorised telemetry, an agreed retention period, and defined sensitivity constraints. BilgeQor triages findings and produces relevant IOC or IOA artefacts plus detection-gap recommendations for the agreed window. It is a scoped request-first engagement, not 24/7 monitoring, SOC or MDR, live containment, recovery, or proof that no compromise exists.

Run a time-bounded, hypothesis-driven hunt across agreed telemetry sources to surface indicators, suspicious activity, and gaps that automated alerts may have missed.

Scope-defined engagement

Good fit if

  • ✓You have authorised specialist assessment with agreed target, scope, and test window or rules of engagement
  • ✓You need scoped, bounded evaluation within explicitly confirmed parameters
  • ✓You want documented findings and prioritised observations from a controlled engagement
  • ✓You understand this is a scoped assessment, not continuous protection or guaranteed outcome

Not a fit if

  • –You need casual scanning or routine vulnerability checks
  • –You require emergency live response or unauthorised testing
  • –You expect guaranteed exploit discovery or complete protection
  • –You need 24/7 monitoring, MDR, or continuous threat hunting beyond scoped engagement

Ideal For

  • Security teams that collect telemetry but have not yet performed a structured hunt against it
  • Organisations preparing for an audit, board review, or customer assurance milestone that benefits from documented hunt findings
  • Teams with a specific concern, hypothesis, or recent change they want examined within a defined window
  • Businesses that want an independent set of eyes on their telemetry without committing to a continuous monitoring contract

What We Evaluate

  • Agreed hunt hypotheses defined and prioritised during scoping
  • Review of agreed telemetry sources within the agreed time window — endpoint, identity, cloud, network, or application logs as in scope
  • Investigation of suspicious patterns identified during the hunt
  • Triage of findings into informational, suspicious, and confirmed-of-interest categories
  • Indicator of compromise (IOC) and indicator of attack (IOA) artefacts where applicable to the agreed hypotheses

Deliverables

Hunt plan documenting hypotheses, telemetry sources, and the agreed hunt window
Findings report with triage, evidence references, and context for each item of interest
IOC and IOA artefacts in a format agreed during scoping
Recommendations for detection coverage, telemetry gaps, and follow-up investigation
Joint debrief covering the hunt approach, findings, and prioritised next steps
Optional: scoped follow-up hunt against new hypotheses, separately agreed

Prerequisites & Authorisation

  • +Written authorisation from the data owner to access the agreed telemetry sources
  • +Agreed list of telemetry sources, retention windows, and access method confirmed in writing
  • +Approved hunt window with defined start and stop times
  • +Agreed hunt hypotheses and any sensitivity constraints documented before work begins
  • +Named primary and backup points of contact reachable throughout the agreed hunt window
  • +Provider, cloud, or identity-platform approval obtained where required for telemetry access

Exclusions & Boundaries

  • This is a time-bounded engagement, not a continuous monitoring or MDR arrangement
  • Twenty-four-hour SOC operation, alert response on-call, and managed detection are not included
  • Live incident response, containment, and recovery execution are not included unless separately scoped
  • Deployment of new telemetry, agents, or logging pipelines is not included unless separately agreed
  • This engagement does not guarantee that all threats present in the environment will be discovered
  • No certification, accreditation, or compliance attestation is issued by this engagement
  • Remediation implementation of identified weaknesses is not included unless separately scoped

How It Works

1

Scoping and hypothesis definition

We agree on hunt hypotheses, in-scope telemetry sources, the hunt window, access method, sensitivity constraints, and stop conditions. Everything is documented in writing before work begins.

2

Authorisation and access

Written authorisation from the data owner and any required provider approvals are confirmed. Access to the agreed telemetry sources is established within the agreed boundaries.

3

Hunt execution

We run the agreed hypotheses against the in-scope telemetry within the agreed window, investigating suspicious patterns and triaging findings as they emerge.

4

Reporting

We deliver the findings report, IOC and IOA artefacts where applicable, recommendations on detection and telemetry gaps, and follow-up investigation priorities.

5

Debrief

We run a joint debrief covering the hunt approach, findings of interest, and prioritised next steps for your security and engineering stakeholders.

Request scope first. We confirm target, authorization, test window and rules of engagement in writing before any later commercial step. This page does not take payment or start specialised work. No specialised work starts before scope authorization.

Scope & Quotation

Final scope and quotation depend on authorised target, environment, and agreed testing conditions.

Frequently Asked Questions

Ready to discuss your scope?

Tell us about your target, environment, and testing window. We will return a scoped quotation.