Use case · Hunting
Threat hunting
Hunting is the first thing to be postponed and the last thing to be resourced. It requires uninterrupted time from your most experienced people, which is exactly what an incident queue consumes.
Runs on
SIEM · EDR · cloud · identity · threat intelligence
Autonomy
levels 1 to 3
The problem today
Hunting happens when there is time, and there is never time
A hunt is a hypothesis, a set of queries across several tools, and the patience to work through the results. Each step is straightforward and the whole is expensive, so hunts become a quarterly exercise rather than a standing capability.
The knowledge produced usually leaves with the analyst who produced it, because there is nowhere durable to put it.
What CloudPeek does
One pass, with the reasoning attached.
What you get
Outcomes, not activity.
Related use cases
Triage
Incident triage
Detection volume outruns the rota, so the queue decides what gets looked at rather than the risk. CloudPeek works each one and either escalates it with evidence or closes it with a written reason.
Investigation
Investigations
When triage escalates, the real work starts: reconstructing a timeline across sources, establishing scope, reaching a root cause and writing it up so somebody else can act on it.
Identity
Identity compromise
Impossible travel, token reuse, consent grants and privilege escalation, investigated against sign in history, device posture and known travel patterns.