Secure AI AgentsUSD 100 in free credits for 7 days.Start now!
UPX
AI Agents
MCP
Offensive Security
UPX

With over 20 years of experience, UPX specializes in cybersecurity engineering for critical environments and the protection of high-complexity, AI-driven operations.

Ask AI about UPX

Products

  • Connected Accounts
  • AI Agents

Managed Security

  • SOC 24/7
  • CrowdStrike Falcon (EDR)
  • Threat Intelligence (CTI)
  • Penetration Testing

Resources

  • Blog
  • Documentation
  • Status

Company

  • About Us
  • Contact
  • Careers
SOC 2 Type IIISO 27001

© 2026 UPX - All rights reserved.

PrivacyTermsCookiesData rightsDo not sell my info
talk@upx.comMiami, FL
  1. Home
  2. Products
  3. Managed Security
  4. Threat Intelligence (CTI)

Managed Security

Threat Intelligence and Proactive Hunting

Find malicious activity that never raised an alert. UPX analysts cross external threat intelligence with your environment's telemetry to investigate behavior that slips past traditional defenses.

Talk to a specialistSee what you get
  • Overview
  • Benefits
  • Services
  • How it works
  • What we hunt
  • MITRE ATT&CK
  • Deliverables
  • Integrations
  • FAQ

Companies that trust UPX

  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO
  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO
  • Bradesco
  • Nubank
  • BTG Pactual
  • Totvs
  • Ascenty
  • Live!
  • G4 Educação
  • EVEO

Overview

Sophisticated attacks use legitimate credentials, native system tooling and quiet movement to stay in the environment without tripping detection rules.

SIEM, EDR and XDR find what they already know. Proactive hunting starts from a different question: instead of waiting for an alert, analysts form hypotheses based on threat intelligence and look for evidence that something is already happening.

Traditional detection and proactive hunting, side by side
Compared aspectTraditional detectionProactive hunting
Starting pointAlert raised by SIEM, EDR or XDRIntelligence-driven hypothesis
What it findsKnown threats, with a signature or ruleBehavior with no signature
Depends on an alertYesNo
OutcomeInvestigation of one eventA discovery and a new detection rule

Benefits

Find what raised no alert

Active investigation of signals that traditional controls did not identify.

Investigate with context

Intelligence on campaigns, techniques and infrastructure relevant to your environment and industry.

Reduce dwell time

The sooner an adversary is found, the smaller the impact and the cost of the response.

Strengthen your detections

Every finding can become a detection rule, an indicator or a hypothesis for SIEM, EDR and other controls.

Two services, one program

Intelligence defines what to look for. Hunting verifies whether it is happening in your environment. Each loses value without the other.

What each of the two services delivers
Threat IntelligenceInformation about threats, campaigns, techniques and indicators, organized in the context of your environment.Proactive Hunting (Threat Hunting)Active, analyst-led investigation of signals that controls have not identified yet.
Indicators of compromise (IOCs)Intelligence-based hypotheses
Tactics, techniques and procedures (TTPs)Evidence search across environment telemetry
Emerging campaignsCase validation and reconstruction
Exploited vulnerabilitiesScope, assets, identities and timeline
Malicious infrastructureHandoff for containment
Adversary contextNew detection rules

How it works

What goes in, what hunting does, and what comes out

A continuous cycle: what is learned in each round goes back into collection, and the next hunt starts from a better-known environment.

Collection

  • Logs and SIEMEvent
  • EDR telemetryLOG
  • Identity and cloudAccess

Investigation

UPX analysts + automation

Investigation under way

  • Correlate
  • Form hypotheses
  • Huntrunning
  • Investigate
Intelligence-drivenMITRE ATT&CK

Output

Result

Evidence and context

  • Threat identified, with scope and timeline
  • Recommendations for containment and remediation
  • New detection rules and hypotheses

Automation for volume, analysts for judgment

AI and automation process millions of events and surface patterns. Sophisticated threats, however, do not always behave predictably: it is UPX specialists who connect evidence, validate hypotheses and confirm what is in fact a threat.

What we hunt

Behavior, not signatures. That is why the search starts from hypotheses rather than ready-made rules.

Lateral movement

Suspicious progression across systems, identities and assets.

Credential abuse

Authentications and access that do not match expected patterns.

Persistence

Mechanisms used to keep access to the environment.

Defense evasion

Behavior aimed at bypassing security controls.

Suspicious execution

Processes, scripts and activity outside expected behavior.

Indicators of compromise

Evidence tied to files, domains, IPs and malicious infrastructure.

Investigation structured by MITRE ATT&CK

Findings are mapped to the framework's tactics and techniques, which makes clear where in the attack each one fits.

Investigation structured by MITRE ATT&CK
IDTacticWhat we investigateTypical sources
TA0001Initial AccessHow access to the environment beganEmail, proxy, identity
TA0002ExecutionCode running on the compromised assetEDR/XDR
TA0003PersistenceMechanisms for keeping accessEDR/XDR, system logs
TA0004Privilege EscalationGaining additional permissionsEDR/XDR, IAM
TA0005Defense EvasionBypassing security controlsEDR/XDR, audit logs
TA0006Credential AccessObtaining valid credentialsIdentity, EDR/XDR
TA0007DiscoveryMapping the environment from insideEDR/XDR, network
TA0008Lateral MovementProgression to other systemsNetwork, identity, EDR/XDR

Simplified reading. The tactics and techniques assessed in each case depend on the environment and the available data sources.

What you get

The result of a hunt is not one more alert in the queue. It is evidence, context and knowledge that goes back into your controls.

  • Threats identified

    Evidence and behavior found during the investigations.

  • Technical context

    Related assets, identities, techniques and possible impact.

  • Actionable recommendations

    Containment, remediation and attack surface reduction actions.

  • New detections

    Rules and indicators to strengthen SIEM, EDR and other controls.

Works with the tools you already have

Hunting uses signals from the technologies present in the environment to widen the context of each investigation. No tool needs to be replaced.

SIEM

Correlated logs and events

EDR / XDR

Endpoint processes and activity

Identity

Authentications and privileges

Cloud

Platform and audit logs

Network

Connections and traffic

CTI

External intelligence

FAQ

Frequently asked questions

  • What is the difference between threat intelligence and proactive hunting?

    Threat intelligence gathers information about adversaries, campaigns, techniques and indicators. Proactive hunting uses that context to actively look, inside your environment, for signs that those threats are already present.
  • Does hunting need an alert to start?

    No. Hunting starts from hypotheses formed out of intelligence and knowledge of the environment, precisely to find activity that raised no alert.
  • I already have SIEM and EDR. Why do I need proactive hunting?

    SIEM and EDR detect what their rules and signatures know. Attacks that use legitimate credentials and native tooling can pass without an alert. Hunting uses data from those same tools to look for that behavior.
  • Do I have to replace my security tools?

    No. The service works with the technologies already present in the environment, such as SIEM, EDR/XDR, identity, cloud and network.
  • Do the investigations follow a framework?

    Yes. Investigations are structured by MITRE ATT&CK, mapping each piece of evidence to the tactics and techniques used by adversaries.
  • Does the service replace a 24/7 SOC?

    No. Hunting complements continuous monitoring. It can be contracted standalone or integrated with the UPX 24/7 SOC, which runs containment and response once a threat is confirmed.

Get started

Assess proactive hunting in your environment

Talk to a specialist to define scope, data sources and targets.

Talk to a specialist