Group Purchasing
Group Purchasing

SANS 2024 Threat Hunting Survey: Hunting for Normal Within Chaos

SANS 2024 Threat Hunting Survey: Hunting for Normal Within Chaos (PDF, 2.72MB)Published: 19 Mar, 2024
Created by:
Mathias FuchsJosh Lemon
Mathias Fuchs & Josh Lemon

The SANS 2024 Threat Hunting Survey: Hunting for Normal Within Chaos, published by SANS Institute in March 2024, measured how organizations conducted threat hunting over the past year, in its ninth consecutive year of fielding this research. The survey drew responses from security professionals across industries including cybersecurity, technology, banking and finance, and education, covering methodology adoption, outsourcing trends, threat actor detection, and the sources hunters rely on to track attacker techniques.

Key findings:

  • 51% of organizations now have formally defined threat hunting methodologies, up sharply from 35% in 2023
  • Lack of skilled staff remains the top barrier to effective threat hunting, though it dropped from 73% in 2023 to 50% in 2024
  • Business email compromise (BEC) overtook ransomware as the most common threat detected through hunting, found by 68% of respondents versus 64% for ransomware
  • Outsourced threat hunting rose sharply, with 37% of organizations now outsourcing versus only 37% reporting they did not outsource in 2023
  • 64% of organizations formally measure the success of their threat hunting efforts, up from just 34% in 2023, and 62% of those report measurable security posture improvements
  • Vendor blogs and papers (59%) and independent blogs (59%) are the top sources hunters use to track new attacker techniques, ahead of commercial intelligence providers (55%)
  • Concerns about data quality or quantity rose from 34% to 44% year over year, and worries about the lack of common data standards grew from 26% to 33%
  • "Living off the land" is the leading tactic seen in nation-state attacks, reported by 76% of respondents, while custom malware leads ransomware-related tactics at 61%
  • 47% of organizations say available human resources now shape which threat hunting methodology they select, a sharp rise from just 21% in 2023
  • The chief information security officer (CISO) is the leading contributor to threat hunting methodology development, with 40% involvement, ahead of external entities (35%) and incident response teams (33%)
  • Looking ahead, 47% of organizations plan to integrate AI and machine learning into their threat hunting operations

The survey points to a threat hunting discipline that is maturing quickly on paper, with more formal methodologies and more organizations measuring their own results, but still constrained by the same resourcing pressures. Staffing shortages are pushing organizations toward outsourcing and toward methodologies shaped by available headcount rather than by the threat landscape itself, even as data volume and inconsistency emerge as a fast-growing complication. The rise of BEC as the top detected threat, ahead of ransomware, also signals a shift in what hunters are actually finding versus what dominates headlines.

Respondents spanned a broad range of industries, led by cybersecurity (15%), technology (13%), banking and finance (13%), and education (10%), with organizations ranging from fewer than 100 employees to more than 100,000. About 65% of respondents were headquartered in the United States, and the top roles represented were security administrators/analysts, SOC analysts, and business managers.

FAQ

Meet the experts