Start from a neutral baseline and add what matters to you. Criteria are labeled by source — the platform baseline is architecture-neutral; buyer-contributed criteria are shown separately.
Build your evaluation
no account needed
Match on your requirements
no account needed
This evaluation is stored in your browser only. We cannot see it, and it is not tied to any account. Save it to a link or create an account to keep it across devices — you can export it at any time either way.
1. Weight what matters
25 criteria
baselineWhat data sources does the hunting platform query — EDR telemetry, network logs, cloud audit logs, identity logs — natively, and what is the typical query latency across a realistic data volume (e.g., 30 days of enterprise EDR telemetry)?
baselineDescribe the hypothesis-driven hunting workflow — does the platform provide a structured way to document a hunt hypothesis, track findings, and convert a successful hunt into a permanent detection rule, with a customer reference on hunt-to-detection conversion?
baselineWhat pre-built hunt content is provided — curated hunt packages mapped to MITRE ATT&CK techniques, updated as new adversary TTPs emerge — and how frequently is this content refreshed?
baselineHow does the platform support retrospective hunting — when a new IOC or TTP is published, can historical telemetry be re-queried automatically, and what is the retention window available for retrospective analysis?
baselineDetail collaborative hunting features — can multiple analysts work a hunt together with shared notes/timelines, and does the platform track hunting metrics (hours invested, findings rate, detections produced) to justify the program's value?
baselineWhat machine-assisted hunting exists — anomaly detection or ML-driven lead generation to surface hunt candidates, versus purely manual query-driven hunting?
baselineExplain integration with the broader SOC workflow — can a hunt finding be escalated directly into the SIEM/SOAR/case-management system with full context preserved, or does it require manual re-entry?
baselineWhat analyst skill level does the platform assume — does it provide guided/templated hunts suitable for a junior analyst, or does it require deep query-language expertise that only senior hunters have?
baselineWhat is the pricing model — per data source, per analyst seat, or a flat platform tier — and how does cost scale as the organization's data volume and hunting-program maturity both grow?
baselineWhen a hunt uncovers evidence of an active, ongoing compromise (not just a historical artifact), is there a fast-track escalation path directly into incident response, and what is a customer-referenced example of a hunt finding leading to real-time containment?
baselineDetail historical trend reporting on hunting-program maturity (hunts conducted, findings-to-detection conversion rate, MITRE ATT&CK coverage achieved through hunting) over time, suitable for demonstrating program value to leadership.
baselineWho within the organization gets access to hunt findings and queries, and is there role-based access control given that hunting reveals both real threats found and, implicitly, what the SOC is and isn't actively looking for?
baselineHow does this platform relate to the customer's existing detection-engineering tooling — is threat hunting a genuinely distinct, hypothesis-driven discovery activity, or does it substantially duplicate rule-authoring/testing capability a detection-engineering platform already provides?
baselineWhat categories of threats or attack techniques does the platform's hunting methodology explicitly struggle with or not cover well (e.g., living-off-the-land techniques, insider threats), and is the vendor willing to disclose these limitations rather than implying comprehensive coverage?
baselineHow consistent is hunting capability and data-source access across a multi-cloud/hybrid environment — is querying equally deep across AWS, Azure, GCP, and on-prem telemetry, or meaningfully shallower for one environment?
baselineWhat is a customer-referenced onboarding timeline for building a hunting program from scratch (no prior formal hunting practice) — including analyst training, hypothesis-library setup, and the first genuinely productive hunt — and what customer-side effort does that require?
baselineDemonstrate the technology's advanced analytics capability to enable the user to identify systems that have been compromised and pinpoint where.
baselineConduct proactive threat hunting using Microsoft-native tools and available telemetry, collaborating with agency staff to identify emerging risks and suspicious activity patterns.
baselineConduct proactive and reactive threat hunting across all of the housing finance agency's environments.
baselineDo you have expertise in security monitoring, threat hunting, incident containment, and response? If so, describe.
baselineUse algorithms and tools to actively hunt for attacks in large volumes of data, create alerts passed to analysts (using a big data platform for collection/analysis), define/develop/implement/update/maintain a Hunting Framework with strategic hunt missions and IOC search from threat intelligence, and create a knowledge base of IOCs.
baselineThe Solution should detect threats from various attack vectors (malware, web application attacks, network attacks, watering hole attacks, DNS attacks, insider threat, data exfiltration) using machine learning across a minimum set of sources: Netflow, IPS/IDS, Proxy, WAF, Windows logs, DNS, FW.
baselineNetwork Threat Hunting should leverage Netflow, Proxy, DNS, IPS, VPN, Firewall, AD/Windows and Email logs to enable hunting for Lateral Movement, Malware Beaconing, Data Exfiltration, Watering Hole, Targeted network attacks, and Dynamic DNS attacks, and must be capable of identifying suspicious or hitherto undiscovered communication patterns.
baselineService provider should submit a monthly threat hunting report based on threat hunting performed on logs generated for the financial institution.
baselineContractor shall execute hypothesis-driven threat hunting to identify abnormal behavior evading automated detections, conducting daily proactive hunting within all SIEMs and telemetry sources based on vulnerability/threat reports and intelligence feeds; document all hunting investigations in Splunk (or approved mechanism) with a Knowledge Base article created/linked within 5 business days of every closed investigation.
Signing up adds sharing with your team, sending this as an RFP to vendors, and private document sharing. Nothing above is taken away, and nothing here is sent anywhere until you choose to.
Platform baseline
neutral · staff-reviewed
RFIWhat data sources does the hunting platform query — EDR telemetry, network logs, cloud audit logs, identity logs — natively, and what is the typical query latency across a realistic data volume (e.g., 30 days of enterprise EDR telemetry)?Answer key — what a strong answer shows
Look for named source breadth and a real query-latency figure at realistic scale — a hunting tool that takes minutes per query breaks the interactive investigation workflow hunting depends on.
RFPDescribe the hypothesis-driven hunting workflow — does the platform provide a structured way to document a hunt hypothesis, track findings, and convert a successful hunt into a permanent detection rule, with a customer reference on hunt-to-detection conversion?Answer key — what a strong answer shows
The point of hunting is feeding back into detection engineering — look for a real conversion workflow and a customer-referenced example, not just ad-hoc querying with no feedback loop.
RFIWhat pre-built hunt content is provided — curated hunt packages mapped to MITRE ATT&CK techniques, updated as new adversary TTPs emerge — and how frequently is this content refreshed?Answer key — what a strong answer shows
Look for a stated content-refresh cadence and ATT&CK mapping; a platform with only a generic query language and no curated starting content requires the buyer to build hunting expertise from scratch.
RFIHow does the platform support retrospective hunting — when a new IOC or TTP is published, can historical telemetry be re-queried automatically, and what is the retention window available for retrospective analysis?Answer key — what a strong answer shows
Retrospective hunting against newly-disclosed threats is high-value; look for a stated retention window and automated re-query capability, not manual historical log-diving.
RFPDetail collaborative hunting features — can multiple analysts work a hunt together with shared notes/timelines, and does the platform track hunting metrics (hours invested, findings rate, detections produced) to justify the program's value?
From other buyers
crowdsourced · anonymized
💬
No buyer-contributed criteria yet
Verified buyers can suggest criteria (anonymized before pooling).
Answer key — what a strong answer shows
Hunting programs need to justify their own budget — look for built-in program metrics (findings-per-hour, detections produced), not just individual analyst tooling with no program-level reporting.
RFIWhat machine-assisted hunting exists — anomaly detection or ML-driven lead generation to surface hunt candidates, versus purely manual query-driven hunting?Answer key — what a strong answer shows
ML-assisted lead generation helps hunters prioritize where to look in high-volume environments; a purely manual query tool puts the entire discovery burden on analyst intuition.
RFPExplain integration with the broader SOC workflow — can a hunt finding be escalated directly into the SIEM/SOAR/case-management system with full context preserved, or does it require manual re-entry?Answer key — what a strong answer shows
Look for direct escalation with context preservation (not a screenshot-and-retype handoff) — friction here is why hunting findings die on the vine in many organizations.
RFIWhat analyst skill level does the platform assume — does it provide guided/templated hunts suitable for a junior analyst, or does it require deep query-language expertise that only senior hunters have?Answer key — what a strong answer shows
Look for a genuine on-ramp for less experienced analysts (guided hunts, templates) — a tool that only senior hunters can use doesn't scale a hunting program.
RFIWhat is the pricing model — per data source, per analyst seat, or a flat platform tier — and how does cost scale as the organization's data volume and hunting-program maturity both grow?Answer key — what a strong answer shows
Look for transparent, predictable scaling economics; a vendor unable to project cost at meaningfully higher data volume creates real budget risk for a growing hunting program.
RFPWhen a hunt uncovers evidence of an active, ongoing compromise (not just a historical artifact), is there a fast-track escalation path directly into incident response, and what is a customer-referenced example of a hunt finding leading to real-time containment?Answer key — what a strong answer shows
A hunt finding indicating active compromise deserves IR-severity escalation, not routine hunt-documentation workflow — ask for a specific fast-track mechanism and a real customer example.
RFIDetail historical trend reporting on hunting-program maturity (hunts conducted, findings-to-detection conversion rate, MITRE ATT&CK coverage achieved through hunting) over time, suitable for demonstrating program value to leadership.Answer key — what a strong answer shows
Trend-over-time program-maturity reporting is a distinct capability from individual hunt documentation — confirm this exists as a maintained, exportable report.
RFIWho within the organization gets access to hunt findings and queries, and is there role-based access control given that hunting reveals both real threats found and, implicitly, what the SOC is and isn't actively looking for?Answer key — what a strong answer shows
Hunt queries and findings reveal SOC blind spots and priorities — role-based access control over this specific asset is an often-overlooked consideration, similar to detection-rule sensitivity.
RFPHow does this platform relate to the customer's existing detection-engineering tooling — is threat hunting a genuinely distinct, hypothesis-driven discovery activity, or does it substantially duplicate rule-authoring/testing capability a detection-engineering platform already provides?Answer key — what a strong answer shows
This is a real, common buyer question given the functional overlap and natural hunt-to-detection pipeline — a vendor should give an honest answer about the boundary and complementarity.
RFIWhat categories of threats or attack techniques does the platform's hunting methodology explicitly struggle with or not cover well (e.g., living-off-the-land techniques, insider threats), and is the vendor willing to disclose these limitations rather than implying comprehensive coverage?Answer key — what a strong answer shows
A vendor willing to disclose genuine gaps in hunting coverage is more credible than one implying their platform catches everything — ask directly for known limitations.
RFIHow consistent is hunting capability and data-source access across a multi-cloud/hybrid environment — is querying equally deep across AWS, Azure, GCP, and on-prem telemetry, or meaningfully shallower for one environment?Answer key — what a strong answer shows
Ask for an honest per-environment coverage breakdown; uneven hunting depth across environments is a common real gap a vendor should disclose rather than obscure.
RFPWhat is a customer-referenced onboarding timeline for building a hunting program from scratch (no prior formal hunting practice) — including analyst training, hypothesis-library setup, and the first genuinely productive hunt — and what customer-side effort does that require?Answer key — what a strong answer shows
Strong answers give a concrete, customer-validated timeline for starting a program from zero, not just onboarding an already-mature hunting team, and are honest about the customer-side effort required.
RFPDemonstrate the technology's advanced analytics capability to enable the user to identify systems that have been compromised and pinpoint where.
RFPConduct proactive threat hunting using Microsoft-native tools and available telemetry, collaborating with agency staff to identify emerging risks and suspicious activity patterns.
RFPConduct proactive and reactive threat hunting across all of the housing finance agency's environments.
RFPDo you have expertise in security monitoring, threat hunting, incident containment, and response? If so, describe.
RFPUse algorithms and tools to actively hunt for attacks in large volumes of data, create alerts passed to analysts (using a big data platform for collection/analysis), define/develop/implement/update/maintain a Hunting Framework with strategic hunt missions and IOC search from threat intelligence, and create a knowledge base of IOCs.
RFPThe Solution should detect threats from various attack vectors (malware, web application attacks, network attacks, watering hole attacks, DNS attacks, insider threat, data exfiltration) using machine learning across a minimum set of sources: Netflow, IPS/IDS, Proxy, WAF, Windows logs, DNS, FW.
RFPNetwork Threat Hunting should leverage Netflow, Proxy, DNS, IPS, VPN, Firewall, AD/Windows and Email logs to enable hunting for Lateral Movement, Malware Beaconing, Data Exfiltration, Watering Hole, Targeted network attacks, and Dynamic DNS attacks, and must be capable of identifying suspicious or hitherto undiscovered communication patterns.
RFPService provider should submit a monthly threat hunting report based on threat hunting performed on logs generated for the financial institution.
RFPContractor shall execute hypothesis-driven threat hunting to identify abnormal behavior evading automated detections, conducting daily proactive hunting within all SIEMs and telemetry sources based on vulnerability/threat reports and intelligence feeds; document all hunting investigations in Splunk (or approved mechanism) with a Knowledge Base article created/linked within 5 business days of every closed investigation.