{"data":{"id":"RA-10","name":"Threat Hunting","family":"RA","family_name":"Risk Assessment","withdrawn":false,"description":"a. Establish and maintain a cyber threat hunting capability to:\n1. Search for indicators of compromise in organizational systems; and\n2. Detect, track, and disrupt threats that evade existing controls; and\nb. Employ the threat hunting capability [Assignment: organization-defined frequency].","supplemental_guidance":"Threat hunting is an active means of cyber defense in contrast to traditional protection measures, such as firewalls, intrusion detection and prevention systems, quarantining malicious code in sandboxes, and Security Information and Event Management technologies and systems. Cyber threat hunting involves proactively searching organizational systems, networks, and infrastructure for advanced threats. The objective is to track and disrupt cyber adversaries as early as possible in the attack sequence and to measurably improve the speed and accuracy of organizational responses. Indications of compromise include unusual network traffic, unusual file changes, and the presence of malicious code. Threat hunting teams leverage existing threat intelligence and may create new threat intelligence, which is shared with peer organizations, Information Sharing and Analysis Organizations (ISAO), Information Sharing and Analysis Centers (ISAC), and relevant government departments and agencies.","enhancements":[],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"nist_800_53":{"rev5":{"id":"RA-10","name":"Threat Hunting","description":"a. Establish and maintain a cyber threat hunting capability to:\n1. Search for indicators of compromise in organizational systems; and\n2. Detect, track, and disrupt threats that evade existing controls; and\nb. Employ the threat hunting capability [Assignment: organization-defined frequency].","discussion":"Threat hunting is an active means of cyber defense in contrast to traditional protection measures, such as firewalls, intrusion detection and prevention systems, quarantining malicious code in sandboxes, and Security Information and Event Management technologies and systems. Cyber threat hunting involves proactively searching organizational systems, networks, and infrastructure for advanced threats. The objective is to track and disrupt cyber adversaries as early as possible in the attack sequence and to measurably improve the speed and accuracy of organizational responses. Indications of compromise include unusual network traffic, unusual file changes, and the presence of malicious code. Threat hunting teams leverage existing threat intelligence and may create new threat intelligence, which is shared with peer organizations, Information Sharing and Analysis Organizations (ISAO), Information Sharing and Analysis Centers (ISAC), and relevant government departments and agencies.","related_controls":["CA-02","CA-07","CA-08","RA-03","RA-05","RA-06","SI-04"],"baseline_low":false,"baseline_moderate":false,"baseline_high":false,"baseline_privacy":false,"new_in_rev5":true,"changes_from_rev4":"New control in Rev 5."}},"compliance_mappings":{"iso_27001_2022":["A.5.7"],"iso_27002_2022":["5.7"],"cobit_2019":[],"pci_dss_v4":[],"nist_csf_2":["DE.AE-06","DE.AE-07","ID.RA-03"],"cis_controls_v8":[],"soc2_tsc":[],"finos_ccc":[],"iso_42001_2023":[],"iec_62443":[],"asd_e8":[],"nis2":[],"apra_cps_234":[],"mas_trm":["12"],"pra_op_resilience":[],"bsi_grundschutz":[],"anssi":[],"osfi_b13":[],"finma_circular":[],"gdpr":[],"dora":[],"bio2":["5.7"],"rbi_csf":["Annex1.13"],"fisc":[],"lgpd_bcb":["BCB.Art.6"],"hkma_tme1":["TME1.7.4"],"mlps_2":[],"dnb_good_practice":[],"cra":[],"swift_cscf":[],"cbb_tm":["TM-11","TM-12"],"cbuae":["CR-3"],"nca_ecc":["2-13"],"qatar_nia":["RM"],"sama_csf":["1.9","3.6"],"uae_ia":["T2"],"bom_ctrm":["4.1"],"cbe_csf":["CD-1"],"cbn_csf":["Part3.5","Part4"],"sa_js2":["JS2-7.3","JS2-7.6"],"bot_cyber":["Ch3.1","Ch8.1"],"cpmi_pfmi":["CG.DE","CG.ID","CG.SA"],"ecb_croe":["CROE.2.4","CROE.2.6.2","CROE.2.7.1"],"ffiec_is":["II.A","II.A.1","III.A"],"iosco_cyber":["DET-3","ID-3","SA-1"],"sebi_cscrf":["DE.CM","DE.DP","DE.VA","ID.RA","SOC","VAPT"],"cmmc_2":["RA"],"nerc_cip":[],"nrc_73_54":[],"tsa_psd":[],"ieee_1686":[],"ferc_cip":[],"doe_c2m2":[],"api_1164":[],"awia":[],"iaea_nss":[],"pci_pts":[],"fips_140":[],"cbest":["CBEST.2","CBEST.4"],"tiber_eu":["TIBER.RT","TIBER.TTI"],"pci_hsm":[],"common_criteria":[],"isae_3402":[],"fca_sysc_13":[],"fda_21_cfr_11":[],"fda_cyber":["CRA-1","MON-3","ST-2","TM-1"],"hitrust_csf":["09.c","10.e"],"iso_27799":[],"lloyds_ms":["CRM.2","MS10.2"],"naic_ds":[],"nhs_dspt":["NDG-9.8"],"pra_ss1_23":[],"solvency_ii":[],"owasp_masvs_v2":[],"csa_ccm_v4":[],"csa_aicm":[],"ccss_v9":[],"mica":[],"basel_sco60":[],"bssc":[],"sec_custody_digital":[],"dpdpa":[]},"attack_techniques":[{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Proactive threat hunting searches for indicators of privilege-escalation exploitation—such as anomalous process-elevation events, unusual kernel interactions, and exploitation artifacts—that may evade automated detection controls."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Threat hunting proactively searches for evidence of public-facing application exploitation—including web shell artifacts, anomalous application behavior, and post-exploitation indicators—that automated monitoring may miss."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Proactive threat hunting searches for supply chain compromise indicators—such as unexpected software modifications, anomalous build artifacts, and unauthorized code changes—that evade signature-based detection."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Threat hunting proactively searches for lateral movement through remote-service exploitation by analyzing internal traffic patterns, service logs, and post-exploitation artifacts across the environment."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Proactive threat hunting searches for defense-evasion exploitation by examining security-tool integrity, identifying disabled controls, and looking for artifacts indicating adversaries have exploited vulnerabilities to evade detection."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Threat hunting proactively searches for credential-access exploitation by analyzing authentication logs, credential-storage integrity, and memory artifacts that indicate adversaries have exploited vulnerabilities to harvest credentials."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Proactive threat hunting examines software dependencies and development toolchains for compromise indicators—such as unauthorized package modifications, suspicious dependency changes, and build-process anomalies."},{"id":"T1195.002","name":"Compromise Software Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Threat hunting proactively validates software supply chain integrity by examining distributed binaries against trusted baselines, searching for unauthorized modifications that indicate supply chain compromise."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"Generated from NIST SP 800-53 Rev 5 with compliance mappings from framework-coverage data 2026-10-03: nist_csf_2 DE.AE-06 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":[]}}