Hunt team
Responsible for five controls and consulted on twelve — the smallest footprint in the framework, and structurally the most adversarial to it.
What It Is.
Owns. Counterattack. Works the hypotheses that Fuse raises.
Doctrinal origin. The counterattack force. Committed on a hypothesis, at a time of the defender’s choosing, to seize initiative rather than to restore a service.
Hunt is Responsible for avenue-of-approach analysis (KT-3), adversary reachability (KT-4), maneuver effectiveness validation (SM-6), priority cyber intelligence requirements (CE-2) and fusion (CE-3). Five controls, and three of them exist to disprove something the program has claimed: that the routes are enumerated, that the decisive points are out of reach, and that the maneuvers actually do what the scheme says they do.
That is the role. A hunt team is not a third triage tier with a better name, and it is not an incident-response overflow pool. It is committed against a hypothesis raised in Fuse, and its output is a finding about the defense as often as it is a finding about an adversary.
The independence problem is real and worth stating plainly. SM-6 asks hunt to validate the effectiveness of maneuvers that the SOC operates. Where hunt reports to the same leadership that is measured on those maneuvers, the validation is structurally compromised — not because anyone is dishonest, but because the question stops being asked hard. Small agencies cannot always separate the two; those that cannot should say so in the assessment record rather than let the reader assume an independence that does not exist.
Every Control It Touches.
Computed from the RACI each control carries, not written down a second time. If an assignment changes in the manual, this list changes with it.
Accountable0 controls
Answers for the outcome. Exactly one role per control, and it is not delegable.
None. This role holds no accountable assignment anywhere in the framework.
Responsible3 controls
Does the work, or shares it. More than one role may be Responsible for the same control.
Consulted18 controls
Asked before the control is settled, because it holds knowledge the accountable role does not.
Informed57 controls
Told the outcome. Not padding — each of these is a place the role has to be able to reconstruct a decision it did not make.
What It Puts into the Chain.
The outputs declared by every control this role is Accountable or Responsible for, and where each one goes. 10 products across 3 controls.
SM — Scheme of Maneuver
- Corrected effectiveness values feeding the coverage computation
- Moves that failed validation, entering the backlog
- Catalog revision where a form’s assumed indicator proves wrong
EN — Engagement and Pursuit
- Reconstruction that determines a safe restore point
- Observed dwell, correcting the estimate
- New intelligence requirements arising from the engagement
- Scope and magnitude eradication is verified against
- Verified-clean state the rebuild path proceeds from
- Recurrence findings requiring disposition
- Eradication status that communication reports against
What It Depends On.
The inputs those same controls declare. Anything sourced from another control is a dependency on another role; anything marked as outside the framework has to be obtained from the wider organization.
SM — Scheme of Maneuver
- Moves recorded as operational and therefore claiming full credit
- Exercise results, control testing, and observed incident performance
EN — Engagement and Pursuit
- Declared incidents
- Preserved evidence, without which reconstruction cannot run
- Terrain overlay the movement is traced across
- Connection and denied-path register bounding plausible movement
- Reconstruction defining the scope that must be cleared
- Identity-plane revocation, without which eviction is incomplete
- Recovery objectives constraining how long eradication may take
- The authority under which transition is declared
What the Role Has to Be Good At.
A hunt starts from a stated, falsifiable proposition tied to a priority requirement — not from a technique list and not from a calendar slot.
Reachability (KT-4) is answered on permitted paths, but the confirmation that a denied path is actually denied lives in raw data most dashboards summarize away.
SM-6 validation means executing the tradecraft the maneuver claims to stop, safely and with a record, and accepting the result when the maneuver does not stop it.
The most valuable sentence this role produces is “the decisive point is reachable, here is the shortest path.” Everything about the surrounding program will make that sentence expensive to say.
A hunt that found nothing has to leave behind the hypothesis, the data examined and the coverage achieved — otherwise nobody can tell a clean estate from a shallow hunt.
How It Goes Wrong.
Each of these is a way the role can appear to be operating — the artifacts arrive, the chart still shows one accountable party — while producing nothing the defense can use.
The most common death of a hunt capability: it becomes the escalation queue, its hypotheses are never worked, and CE-3 loses its only independent input.
Monthly hunts on a rotating technique list, unconnected to any intelligence requirement. Activity is high, CE-2 closes nothing.
SM-6 findings that are always favorable to the team that owns the maneuvers. Check whether SM-6 has ever produced a finding that cost someone money.
“No findings this quarter” reported as an outcome rather than as an input requiring the hypothesis record to interpret it.
A hunt program defined by its platform rather than by its questions. The platform changes every three years; the questions do not.
Against the Other Five.
The shared count beside each is derived — how many controls the two roles both appear on. The note is authored: what the relationship is actually for, and where it breaks.
The tightest coupling in the framework. Fuse raises the hypothesis, hunt tests it, and the answer returns to the same control (CE-3) with a confidence attached.
Hunt validates what the SOC operates. Keep the reporting lines apart far enough that SM-6 can come back negative.
Hunt is where an Authorizing Official finds out whether the coverage numbers mean anything. Consulted on defensive intent (CG-1) and rules of engagement (CG-3) for exactly that reason.
Hunt operates on ground platform owners run, often in production. That relationship is built before it is needed, or it is not available when it is.
The thinnest relationship of the six — hunt is Consulted on nothing the ISSO is Responsible for except insider risk position (WF-4). Its findings reach governance through CE-3 and CG-4 rather than directly.