Intel 471

SANS 2026 Threat Hunting Survey: The Evolution of Threat Hunting

The 2026 SANS Threat Hunting Survey: The Evolution of Threat Hunting

In 2026, SANS asked 500 security professionals how they hunt, what they find and what holds them back. The answers suggest the community has matured: more than 80% have been hunting for at least two years. Yet teams are struggling with the fundamentals. Data quality and skilled staff are the top barriers, fewer teams are formally measuring hunt effectiveness, and ad hoc methodologies are creeping back.

Meanwhile, adversaries keep blending in to evade conventional detection. Living off the land is the top technique hunters uncover across nation-state, ransomware and organized crime actors — and only behavior-based hunting will find it. Interest in AI-assisted hunting has also cooled as teams take a more measured view of what these tools deliver.

In this report, you'll learn about:

  • How often teams hunt and how long a hunt takes, and why only 9% now rate their program very mature, down from 19% in 2025
  • Why cloud remains the hardest environment to hunt in, and how portable devices became the second hardest
  • The techniques hunters uncover most, from living off the land (73% for nation-state actors) to evidence deletion by ransomware and organized crime groups
  • Why data quality (50%) and skilled staff (45%) top the list of barriers
  • How staffing shapes methodology, with 38% saying available people drive how they hunt, why formal methodologies slipped to 37% from 46% in 2025. SANS recommends adopting an established framework rather than building one from scratch
  • Why only 40% formally measure hunt effectiveness, down from 64% in 2024, even though 70% say hunting improved their security posture
  • Why plans to add AI and ML to hunting fell to 39% from 48% in 2025

Download the SANS 2026 Threat Hunting Survey: The Evolution of Threat Hunting, sponsored by Intel 471, to benchmark your program against peers and see where the threat hunting community is heading.

Loading form...