A Study on Threat Hunters
In today's ever-evolving cybersecurity landscape, the role of threat hunters is becoming increasingly vital. These professionals are the frontline defenders against complex cyber threats. Threat hunters utilize a combination of advanced technical skills, situational awareness, and proactive mindset to protect organizations. This blog post examines comprehensive findings from Victoria University's research on threat hunters, offering insights into their workflows, challenges they face, and capturing significant threat hunter personas.

This blog was written by the CHISEL Group research team at Victoria University, who also authored the report this series is based on.
Our team at the CHISEL Group at Victoria University, in collaboration with OpenText, embarked on a research journey to uncover the nuances behind the threat hunter role. This project, managed by our dedicated researchers, aims to provide a detailed understanding of threat hunters and their tools, workflows, and challenges. As a result, we have developed personas that can aid in the design and development of tools that support threat hunters in their daily tasks.
This post is the second in OpenText's "The Rise of the Threat Hunter" blog series. You can learn more about the series and find links to all our posts here.
Our Research
The team at Victoria University specializes in software, visualization, and social technologies. We explore how technology can help people discover, understand, and share complex information and knowledge. Together, we conducted 20 interviews with threat hunters from various industries and around the world. The data we collected revealed key themes and patterns in the experiences, skills, workflows, and challenges of threat hunters, which we then analyzed using qualitative coding. As a result, we present 17 threat hunter dimensions and have developed four personas in this post.
Our findings are documented in a report reviewed by OpenText's industry experts and can be found here.
Understanding Threat Hunters: Roles, Tools, Skills, and Challenges
Threat hunters play a crucial role in proactively identifying and mitigating security threats before they cause significant damage. On any given day, threat hunters take on a variety of tasks. Threat hunters review use cases, prioritize alerts, generate reports, conduct meetings, manage escalations, develop policies, and manage communications, among other things. In addition, threat hunting team managers provide senior security advisory and support for active incidents and report to managers.
As shown in the list of tasks in the report, the role requires a mix of technical and non-technical skills. Not everyone can perform advanced threat hunting that requires problem-solving and analytical skills, nor can they take complex cybersecurity concepts or research findings and present them clearly and concisely to company leadership. Developing these skills takes time, and this is where continuous learning comes into play.
Continuous learning and staying up-to-date with the latest cybersecurity news and trends is a critical aspect of being a threat hunter. While learning everything through articles and videos is great, continuous learning has an important social aspect that cannot be overlooked. Attending conferences, working with mentors/mentees, and participating in meetings allows threat hunters to share their expertise and gain knowledge. Earning certifications and gaining continuous hunting experience can build confidence for a threat hunter; however, due to the rapidly evolving nature of threats, complete confidence is rare.
Just as with threat hunter skills, both technical and non-technical tools are crucial for identifying and mitigating threats, ensuring solid security measures are in place. To emphasize the variety of tools used by threat hunters, we created a visualization of the tools they reported using during our interviews. Look below.

Each of these tools addresses the challenges that threat hunters or threat hunting teams face, but no tool is perfect. Some remaining challenges include geographically dispersed teams that must contend with global time zones, information overload and fatigue from daily struggles, and the lack of formal handover protocols. Threat hunters are dynamic individuals who encounter many challenges that can be addressed through the development of tools that understand the underlying needs of threat hunters from day one.
Personas
We want to share everything we learned from our research with the cybersecurity community because we understand the value of continuous learning and we truly want to see threat hunters succeed. In addition to our full report, we have compiled four personas that summarize the essential characteristics of threat hunters in a useful format for security managers, product developers, leadership teams, and more.
During our research, we identified 17 fundamental characteristics of threat hunters and converted them into 17 dimensions. You can find the definitions for all 17 dimensions on page 17 of the report.
Here are some of the more interesting and effective dimensions we discovered:
Hunting style (proactive to reactive): This dimension captures a threat hunter's approach to identifying threats. A proactive style is crucial for predicting and reducing potential threats before they cause harm.
Cognitive approach (intuitive/creative to analytical/methodical): This dimension measures how threat hunters process information and solve problems. A balanced approach that combines intuition and analytical skills is essential for effective threat hunting.
Learning strategies (self-taught, trial-and-error, formal certification, mentorship, and collaboration): Continuous learning is essential for threat hunters to develop their skills through various strategies. Effective learning strategies help them stay updated with the latest cybersecurity trends.
Tool environment (commercial to in-house embedded): This dimension represents the types of tools threat hunters use. The ability to leverage both commercial and in-house tools enhances their capacity to detect and respond to threats.
Initiation process (applied to tool leadership): This dimension captures how threat hunters initiate their research. Applied hunters rely on manual techniques and personal expertise, while tool-led hunters use automated tools and software. Understanding this helps organizations balance manual and automated approaches for optimal threat detection.
Validation of findings (peer review for resource use): This dimension reflects how threat hunters validate their discoveries. Some rely on peer reviews and team discussions, while others use established resources and databases. Recognizing this dimension helps ensure comprehensive and accurate threat validation processes.
Using these dimensions, we created four personas inspired by the threat hunters we interviewed. We present Olivia, Jay, Thomas, and Ren as examples of threat hunter personas.

Olivia is a creative team leader who hunts proactively, guides her team, and curates toolsets.
Jay represents a new hire who approaches threat hunting with a problem-solving mindset and strong academic foundations, knowledgeable in analytics and automation.
Thomas, often referred to as the "Cyber Space Cowboy," is an experienced, self-taught threat hunter who uses his intuition and vast experience to identify threats in smaller teams.
Finally, Ren embodies the management role by effectively communicating and collaborating with customers and organizational leadership.
, Alessandra Milani (PhD Student), Arty Starr (PhD Student), Norman Anderson (Undergraduate Student), David Moreno-Lumbreras (Post-Doctoral), and Margaret-Anne Storey (Professor and Canada Research Chair). Significant contributions to this project were made by Callum Curtis (Undergraduate Student), Marcus Dunn (Former Undergraduate Student), and Enrique Larios Vargas (Researcher at Adyen, previously collaborated with UVic). Learn more about the Victoria University CHISEL Group.
Learn More About OpenText Cyber Security
Ready to empower your threat hunting team with products, services, and training to protect your most valuable and sensitive information? Explore our comprehensive portfolio of modern complementary security solutions that provide 360-degree visibility across endpoints and network traffic to help threat hunters and security analysts identify, prioritize, and investigate anomalies and malicious behavior. View our Cyber Security portfolio here.