The SANS 2026 Threat Hunting Survey found that 50% of 500 cybersecurity practitioners and leaders identify inadequate data quality and quantity as their primary threat-hunting obstacle, overtaking skills shortages. Gaps in cloud logging and identity telemetry are particularly damaging because ransomware operators, nation-state actors, organized crime groups, and business email compromise actors increasingly blend into normal administration through living-off-the-land techniques. Ransomware was the threat most frequently uncovered by hunting teams, followed by BEC, nation-state activity, and insider threats.
Threat-hunting program maturity also appears to be declining: only 37% of respondents use a formal hunting methodology, and just 40% formally measure hunt effectiveness, down from 64% in 2024. Organizations also reported weaker security improvements from hunting and reduced near-term plans to deploy AI or machine learning. CISOs should prioritize complete, standardized cloud and identity telemetry, establish repeatable hunting processes, and measure detection and remediation outcomes before expanding advanced analytics investments.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
Only 40% of threat-hunting programs formally measured hunt effectiveness, compared with 64% in 2024. Planned AI or machine-learning adoption declined from 48% in the prior year to about one-third of respondents, while early responses described agentic hunting frameworks that retain analyst decision-making authority.
Ransomware was the threat most commonly found by threat-hunting teams, cited by 55% of respondents, followed by business email compromise, nation-state activity, and insider threats. Respondents identified living-off-the-land techniques as especially prevalent and warned that static hash- and IP-based hunting is insufficient against attackers using legitimate tools.
The survey found that 37% of programs used a formally defined threat-hunting methodology, down from 51% in 2024, while 39% used ad hoc approaches. SANS said formal methodologies help make hunting programs repeatable and defensible.
SANS surveyed 500 cybersecurity practitioners and leaders and reported that data quality and quantity were the leading threat-hunting barrier, cited by 50% of respondents. The survey also identified gaps in cloud logging, identity telemetry, data normalization, and standards as obstacles to effective hunting.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.