Find what raised no alert
Active investigation of signals that traditional controls did not identify.
Managed Security
Find malicious activity that never raised an alert. UPX analysts cross external threat intelligence with your environment's telemetry to investigate behavior that slips past traditional defenses.
Companies that trust UPX
















Sophisticated attacks use legitimate credentials, native system tooling and quiet movement to stay in the environment without tripping detection rules.
SIEM, EDR and XDR find what they already know. Proactive hunting starts from a different question: instead of waiting for an alert, analysts form hypotheses based on threat intelligence and look for evidence that something is already happening.
| Compared aspect | Traditional detection | Proactive hunting |
|---|---|---|
| Starting point | Alert raised by SIEM, EDR or XDR | Intelligence-driven hypothesis |
| What it finds | Known threats, with a signature or rule | Behavior with no signature |
| Depends on an alert | Yes | No |
| Outcome | Investigation of one event | A discovery and a new detection rule |
Active investigation of signals that traditional controls did not identify.
Intelligence on campaigns, techniques and infrastructure relevant to your environment and industry.
The sooner an adversary is found, the smaller the impact and the cost of the response.
Every finding can become a detection rule, an indicator or a hypothesis for SIEM, EDR and other controls.
Intelligence defines what to look for. Hunting verifies whether it is happening in your environment. Each loses value without the other.
| Threat IntelligenceInformation about threats, campaigns, techniques and indicators, organized in the context of your environment. | Proactive Hunting (Threat Hunting)Active, analyst-led investigation of signals that controls have not identified yet. |
|---|---|
| Indicators of compromise (IOCs) | Intelligence-based hypotheses |
| Tactics, techniques and procedures (TTPs) | Evidence search across environment telemetry |
| Emerging campaigns | Case validation and reconstruction |
| Exploited vulnerabilities | Scope, assets, identities and timeline |
| Malicious infrastructure | Handoff for containment |
| Adversary context | New detection rules |
How it works
A continuous cycle: what is learned in each round goes back into collection, and the next hunt starts from a better-known environment.
Collection
Investigation
UPX analysts + automation
Investigation under way
Output
Result
Evidence and context
AI and automation process millions of events and surface patterns. Sophisticated threats, however, do not always behave predictably: it is UPX specialists who connect evidence, validate hypotheses and confirm what is in fact a threat.
Behavior, not signatures. That is why the search starts from hypotheses rather than ready-made rules.
Suspicious progression across systems, identities and assets.
Authentications and access that do not match expected patterns.
Mechanisms used to keep access to the environment.
Behavior aimed at bypassing security controls.
Processes, scripts and activity outside expected behavior.
Evidence tied to files, domains, IPs and malicious infrastructure.
Findings are mapped to the framework's tactics and techniques, which makes clear where in the attack each one fits.
| ID | Tactic | What we investigate | Typical sources |
|---|---|---|---|
| TA0001 | Initial Access | How access to the environment began | Email, proxy, identity |
| TA0002 | Execution | Code running on the compromised asset | EDR/XDR |
| TA0003 | Persistence | Mechanisms for keeping access | EDR/XDR, system logs |
| TA0004 | Privilege Escalation | Gaining additional permissions | EDR/XDR, IAM |
| TA0005 | Defense Evasion | Bypassing security controls | EDR/XDR, audit logs |
| TA0006 | Credential Access | Obtaining valid credentials | Identity, EDR/XDR |
| TA0007 | Discovery | Mapping the environment from inside | EDR/XDR, network |
| TA0008 | Lateral Movement | Progression to other systems | Network, identity, EDR/XDR |
Simplified reading. The tactics and techniques assessed in each case depend on the environment and the available data sources.
The result of a hunt is not one more alert in the queue. It is evidence, context and knowledge that goes back into your controls.
Evidence and behavior found during the investigations.
Hunting uses signals from the technologies present in the environment to widen the context of each investigation. No tool needs to be replaced.
Correlated logs and events
Endpoint processes and activity
Authentications and privileges
Platform and audit logs
Connections and traffic
External intelligence
FAQ
Get started
Talk to a specialist to define scope, data sources and targets.