Business & Technology
How does AI improve the speed of threat hunting?
The introduction of LLM-powered AI SOC platforms is democratising threat hunting by breaking down the technical barriers that have historically limited access to it for senior analysts.
By allowing analysts to translate intent into platform-specific queries using natural, non-technical language, AI eliminates the need for specialised knowledge like Python scripting or proprietary query languages.
Now we know that artificial intelligence can accelerate threat hunting and open it up to a wider set of team members, but exactly how does it achieve this transformation? This article covers exactly how.
Applied to the threat hunting process, AI can:
- Automate evidence gathering
- Suggest where threats can be hunted
- Translate intent into queries
- Provide a reasoning layer that wasn’t there before
- Enable complex, always-on threat hunting
Threat hunting isn’t good enough if it is sporadic, subjective, or based on human timelines: adversaries are attacking at the speed of machines, and AI-enabled ones at that.
Weaving AI deeply into modern threat hunting practices will now only “speed things up,” but change the threat hunting expectation from an occasional benefit to a constant, standard practice.
1. Automating Evidence Gathering (& Saving SOC Cycles)
At the start of a threat hunt, one looming barrier stands in the way: gathering evidence. For the typical SOC, this means toggling between a half dozen tools, taking screenshots, and compiling the case.
With AI, security operations automation becomes a reality. As leading AI SOC platform company Prophet Security explains, “Once a hunt starts, [an AI SOC solution] pulls logs, events, and metadata from integrated sources without requiring the analyst to query each one manually.”
Without the use of AI, this process can take up to an hour with manual investigative querying processes alone: across SIEM, EDR, email, IAM, etc. With AI, that timeline is reduced to less than 20 minutes.
2. Suggesting Threat Hunts: Getting to What Matters
However, before evidence can even be gathered, analysts need to know what they’re hunting: the hypothesis.
Not all SOCs are equipped with the same technical expertise or the same amount of time to do a hunt. The status quo is that threat hunting is currently a proactive measure; something done to stay ahead of threats missed by detection rules and done as a hygienic best practice. Otherwise, threat hunting is a strictly reactive procedure as part of the incident response process, and typically done in response to a recent breach or an upcoming audit.
Either way, feeling ahead of the game or behind it still makes threat hunting seem “special.” The end goal is to make it seem standard.
And neither scenario leaves hunters with all that much time to carefully choose where to start, or what to pursue. With so many possible signals, any one of them could lead to a wider issue – or to a dead end. Getting hours into a hunt only to realise the road leads nowhere is a waste of time and money, and every threat hunter knows the feeling.
AI can suggest the threats worth hunting before anyone even starts looking at the signals. By ingesting telemetry from across all integrated tools (EDR, identity logs, network traffic, SIEM), it creates a baseline of normal behaviour.
When something deviates from normal behavior, it can go one step further by mapping to known attacker techniques (MITRE ATT&CK), and then form a hypothesis about what could be wrong.
Most importantly, not all hypotheses are created equal. AI knows this. It ranks hypotheses by criticality (asset criticality, privilege level, likelihood) and presents hunters with a ranked list: not a best-guess, intuition-inspired direction.
Then, all analysts have to do is ask the right questions.
3. Translating Intent into Queries: No Coding Required
Currently, when analysts want to query systems, they have to speak the respective language. With AI, Large Language Models (LLMs) do this technical heavy lifting for threat hunters. In an AI SOC, even a junior analyst can type in a simple request:
“Where else across the environment was this (flagged) IP seen?”
And AI will use natural language processing to translate the plain-language question into platform-specific query languages (SQL, SPL, KQL): no technical interface required. No manual coding. This not only makes “every analyst a threat hunter,” thereby speeding up how many threat hunts can be performed, but it also makes each hunt faster.
Senior analysts can skip the long lines, the reviewing and editing, and the technical learning curves to searches; instead, they can focus on the actual “thinking” part of threat hunting.
Increasingly, AI is doing even that, too.
4. Providing Additional Reasoning, At Machine Speed
Automation-only tools (SOAR, XDR) may correlate events, but the best AI SOC platforms tell analysts why they happened. Agentic AI is behind that.
By providing an additional reasoning layer, analysts can move more quickly and confidently through hunts, having a built-in backup “brain” at each step.
Agentic AI constructs dynamic attack narratives, building an attack graph across users, hosts, processes, and network connections. It processes and correlates context, tying it into the broader story.
After mapping to MITRE ATT&CK, it can show analysts:
- A timeline of the attack
- A likely attack path
- Any missing steps
These missing steps are where threat hunters fill in. It takes teams from raw logs to the structured intent of the attacker, bypassing hours of analysis, toggling, and piecing together clues along the way.
Now, instead of “Suspicious PowerShell execution” alerts, teams get something like: “Suspicious PowerShell on a domain controller by a rarely used admin account after anomalous login.”
Starting there means starting with a significant head start.
5. Enabling Complex, Always-On Threat Hunting for Max Coverage
Another reason threat hunting with AI is faster than threat hunting without it, is that AI never tires. In traditional setups, humans are the head, foot, and tail of threat hunts. They might operate automated tools, but things don’t happen until they’re at the controls.
While most SOCs run 24/7, small teams and even large enterprises understand how hard (and costly) that can be. Your 3 am threat hunting team is not going to be as sharp, savvy, or awake as your 9 am team.
Or, as AI.
AI-enabled threat hunting through an AI SOC means vigilance that never sleeps, tires, or makes mistakes out of exhaustion. Mental powers are never taxed, and help surface signals that may otherwise be overlooked.
Speed Becomes Consistency
AI makes threat hunting faster. And when things are done faster, they can be done more often.
This benefits large enterprises, who, even at their best, may only conduct threat hunting once a week (or once a day for elite achievers).
This benefits mid-tier organisations that hover somewhere between quarterly threat hunts and even-based threat hunts: trying to stay on top of things but having to split analysts between proactive activities and daily tasks.
And it benefits the smallest companies that struggle to even staff a SOC, much less a SOC full of experienced threat hunters.
For all these teams, AI gives them something they never had: round-the-clock threat hunting, done at machine speed, and proactive security that comes standard.
The Takeaway: At a time when AI-driven threats never sleep, AI-driven threat hunting is more than a nice recommendation. It is the new norm for organisations that understand AI attackers aren’t playing by traditional detection rules, and that they will increasingly be found only via ongoing, AI-powered threat hunts.
Business & Technology
Evri approved after Oxford Botley Road shop wins extension appeal
Nisa Local, which first opened in Botley Road in November, can now be extended after a Planning Inspector overturned Oxford City Council’s rejection.
The proposal is for a steel security shutter and a single-storey rear extension, which would provide more space for new services such as an Evri and two more Cook frozen meal freezers.
The Costa Coffee self-service machine is hoped to be on the front of the shop and will provide more floor space for Bake & Bite and the Oxford-based Natural Bread Company.
Oxford City Council refused permission in March arguing the extension would harm the character and appearance of the property.
Aejal Patel, Nisa manager (Image: Ben Hardy)
However, planning inspector Alexander O’Doherty concluded the impact on the wider area would be limited because the extension would be largely hidden at the rear from public view.
In his decision issued on July 23, the inspector acknowledged that the extension would have some harmful effect on the appearance of the building itself, but said the benefits outweighed that harm.
The inspector noted the shop is “clearly lacking in storage space” and said the additional floor area would help it better serve local residents.
The decision also referenced numerous representations from supporters, with the inspector saying these lent “considerable credence” to the benefits of the scheme.
He added that providing these services within a residential area would encourage walking, cycling and the use of public transport by reducing the need for residents to travel elsewhere by car.
Business & Technology
Witney sweet shop announces closure ‘with heavy heart’
Grumpys Sweet Shop in Fettiplace Road, which operated as a cafe and collectibles shop until it became a sweet shop in 2023, has announced it will close by the end of August.
A statement from the team behind the shop said the ‘difficult decision’ was taken with a ‘heavy heart’.
The final day trading would be Friday, August 28.
READ MORE: New Oxford ‘traffic filter’ scheme launch date announced
The statement said: “This hasn’t been a decision we’ve taken lightly.
“Like so many families and small businesses, we’ve felt the impact of the rising cost of living, and the increasing costs of running a business have made things more challenging than ever.
Sweets (stock photo) (Image: Timm Bursch / Unsplash)
“On top of that, our current lease has came to an end.
“Renewing it would mean committing to another seven years, and after a great deal of thought, we’ve decided that this is the right time for us to close this chapter.
“While we’re incredibly sad to say goodbye, we’d love to see as many of you as possible before we close.
READ MORE: Oxfordshire postcode wins big in Postcode Lottery draw
“From the bottom of our hearts, thank you for making Grumpy’s Sweet Shop so much more than just a business.
“You turned it into a place filled with smiles, laughter, and wonderful memories that we’ll treasure forever.”
The owners added that ‘everything you see in the shop’ is now for sale, and offers will be considered for all fittings and displays.
Business & Technology
£7 billion East West Rail Oxford to Milton Keynes row reignites
The dispute that halted the much-anticipated introduction of new trains to Milton Keynes looked to be coming to be coming to an end.
The Government has been pushing for ‘Driver-Controlled’ or ‘Driver-Only Operation’—a cost-saving method introduced widely on London commuter lines in the 1980s, a move widely condemned by trade unions.
The Department for Transport’s (DfT) plan for trains to be staffed by a driver and a customer service inspector seemed to solve the dispute.
But this did not meet the The National Union of Rail, Maritime and Transport Workers (RMT)’s demands.
The union has been opposing plans to use driver-only trains between Oxford and Milton Keynes Central.
Although the line between Bicester and Bletchley has technically been open since 2024, it has only been used by freight, charter, and test trains.
Chiltern Railways was chosen as the operator and has been advertising for customer service inspectors, instead of guards.
However, these inspectors would not be considered ‘safety-critical,’ meaning the driver would be responsible for opening and closing the doors.
Chiltern Railways stated it has made significant progress in preparing for the line to open to scheduled passenger trains, but no date has been announced.
READ MORE: Cruz Beckham pokes fun at brother Brooklyn amid bitter family fallout
East West Rail Action Group protesting outside Bletchley station (Image: Diana Blamires)
The company said it is continuing to work closely with the The Department for Transport, trade unions, and industry partners.
The National Union of Rail, Maritime and Transport Workers general secretary Eddie Dempsey insisted on the necessity of a guaranteed safety-critical second person aboard trains, citing their essential role in handling a wide range of duties and responding appropriately to ‘dangerous and fast-moving’ situations.
He said: “We need a clear commitment from Chiltern that East West Rail services will not be Driver Only Operation and that a second safety-critical member of staff will be guaranteed.”
Chiltern Railways is set to be renationalised on September 20, when it will be taken over by DfT Operator in preparation for Great British Railways.
45 drivers have been recruited for the new service, but no guards.
The project delays have already taken a significant financial toll.
Six two-carriage trains have accumulated £2.6m in costs due to delays in their lease.
Currently idle in a Bletchley depot, these units are costing the Department for Transport money without generating any fare income.
The Government previously said trains from Oxford to Milton Keynes are being lined up to appear in the December rail timetable.
In a written statement, rail minister Lord Peter Hendy said: “Chiltern worked with Network Rail, the Department for Transport and other operators on the December 2026 timetable and services have been timetabled between Oxford, Winslow, Bletchley and Milton Keynes.”
-
Business & Technology3 weeks agoHSBC UK & Visa test AI shopping with live payments
-
Business & Technology4 weeks agoMouser warns against viral hacks to cool overheating phones
-
Business & Technology3 weeks agoValarian lands USD $50 million backing for sovereign AI
-
Business & Technology4 weeks agoKane tops England influencer rankings after Mexico win
-
Business & Technology4 weeks agoSNP & Palantir launch AI tools for SAP transformations
-
Oxford News4 weeks agoDWP now checking bank accounts for Universal Credit and Pension Credit
-
Oxford Events4 weeks agoHenley Festival 2026 highlights: Five nights of unforgettable performances and festival moments
-
Business & Technology4 weeks agoOde launches free AI voice service for poem recommendations
