Group Purchasing
Group Purchasing

SANS 2027 Threat Hunting Survey Insights: The Hunt for Proof

  • Wed, Aug 25, 2027
  • 10:30AM - 1:30PM EDT
  • English
  • Josh Lemon
  • Industry Research Presentation
Login to register
Webcast Hero

Attackers increasingly rely on valid credentials, trusted tools, and cloud-native services to blend in with legitimate activity. When malicious behavior looks normal, automated detections alone may not be enough. Threat hunting provides another layer of defense—and an opportunity to prove that security operations can uncover what existing controls miss.

Join SANS and industry experts for insights from the 2027 SANS Threat Hunting Survey and an exploration of how modern hunting programs are evolving. Go beyond the data as experts examine how teams are hunting across identity, cloud, endpoint, and network environments; closing critical visibility gaps; and balancing human expertise with detection engineering, automation, and AI.

Expert-led discussions will also tackle a growing question for security teams and leaders: How do you prove threat hunting works?

Why Join?

  • Go beyond the survey results: Hear SANS and industry experts interpret the findings and discuss what they reveal about the state of modern threat hunting.
  • Explore the changing hunt: See how identity, cloud, endpoint, and network telemetry are shaping hunting strategies as attackers increasingly hide within legitimate activity.
  • Examine the role of AI and automation: Learn where detection engineering, automation, and AI are augmenting the hunt—and where human expertise remains essential.
  • Turn hunting into stronger defenses: Explore how teams are using hunts to validate detection coverage, uncover visibility and data-quality gaps, and improve security operations.
  • Prove the value of hunting: Hear expert perspectives on measuring hunt outcomes, demonstrating impact, and making the case for continued investment.
  • Earn 3 CPE credits

Register now to explore the research, hear expert perspectives, and discover how leading teams are moving threat hunting from finding suspicious activity to proving their defenses work.

Meet Your Speaker

Josh Lemon
Josh Lemon

Josh Lemon

Chief Digital Forensics and Incident Response Investigator at SoteriaSec

Josh leads global MDR at Uptycs, defending major international brands, while also serving as an independent DFIR expert advising legal, government, and commercial clients in Australia.

Read more about Josh Lemon