Group Purchasing
Group Purchasing

SANS 2025 Threat Hunting Survey: Advancements in Threat Hunting Amid AI and Cloud Challenges

SANS 2025 Threat Hunting Survey: Advancements in Threat Hunting Amid AI and Cloud Challenges (PDF, 1.15MB)Published: 13 Mar, 2025
Created by:
Josh Lemon
Josh Lemon

Thank you to our sponsors

The SANS 2025 Threat Hunting Survey, published by SANS Institute in March 2025, marks a decade of tracking how organizations evolve their threat hunting capabilities. The survey drew on responses from security practitioners worldwide, covering methodology maturity, staffing and outsourcing trends, AI adoption, cloud visibility challenges, and the adversary tactics most commonly uncovered through threat hunting.

Key findings: • Only 51% of organizations formally measure the effectiveness of their threat hunting, down sharply from 64% in 2024 • Organizations fully outsourcing threat hunting dropped to 30%, down from 37% the prior year, while those managing it entirely in-house rose to 58% • 61% of respondents cite skilled staffing shortages as their primary barrier to threat hunting success • Cloud infrastructure is the single hardest environment to threat hunt in, cited by 39% of respondents, despite being a growing priority area • Ransomware detections through threat hunting fell from 63% to 46% year over year, while nation-state detections rose slightly to 41% • "Living off the land" (LOTL) techniques remain the most prevalent adversary tactic, appearing in 76% of nation-state attacks — unchanged from 2024 • The use of internally built threat-tracking tools rose to 48%, up from 33%, while reliance on commercial intelligence tools declined to 58% from 70% • EDR/XDR ranks as the most critical tool for threat hunting, followed by SIEM and network detection and response (NDR) • 76% of organizations now use vendor blogs and papers as a priority threat intelligence source, up from 59% the prior year • 48% of organizations are prioritizing AI and machine learning integration into their threat hunting tools to improve automation and detection accuracy The survey finds an industry in transition: organizations are pulling threat hunting capabilities in-house and investing in custom tooling, even as they struggle to formally measure whether their hunting programs are working. Cloud visibility remains the most persistent technical gap, and while AI adoption is a stated priority, its measurable impact on catching threat actors so far remains limited. The overall trend points to continued investment in threat hunting as a strategic priority despite budget and staffing constraints. Respondents were drawn primarily from the government, technology, cybersecurity, and banking and finance sectors, spanning organizations from under 1,000 employees to more than 50,000, with security administrators/analysts, SOC analysts, and security managers or directors making up the largest respondent roles.

Securing the Future with Microsoft Defender for Cloud: Best Practices and Insights

Related Webcast

Learn how to enhance your cloud security posture through actionable insights and use cases involving Microsoft Defender for Cloud.

Podcast

FAQs

Meet Your Author

Josh Lemon
Josh Lemon

Josh Lemon

Principal Instructor

Josh leads global MDR at Uptycs, defending major international brands, while also serving as an independent DFIR expert advising legal, government, and commercial clients in Australia.

Read more about Josh Lemon