Introducing the PEAK Threat Hunting Framework

Cybersecurity is an ever-evolving game of cat and mouse. As security experts come up with new ways to protect valuable digital assets, cybercriminals develop craftier techniques to bypass these defenses.

Enter threat hunting — the proactive practice of ferreting out those sneaky cyber-rodents. Or, if you insist on a more formal definition, “any manual or machine-assisted process intended to find security incidents missed by an organization’s automated detection systems.” Either way, hunting is a great way to drive improvement in automated detection and help you stay ahead of the attackers.

Of course, we want our threat hunting operations to be a well-oiled machine, something documented and repeatable so we’re not continually making things up as we go. That's where the PEAK Threat Hunting Framework, brought to you by SURGe by Splunk, comes into play.

In this article, we'll introduce you to PEAK, a cutting-edge approach to threat hunting, designed to adapt and thrive in today's dynamic cybersecurity landscape. Over seven articles, we've described in detail how to hunt with PEAK:

  1. Introducing the PEAK Threat Hunting Framework (this very article!)
  2. Hypothesis-Driven Hunting with the PEAK Framework
  3. Baseline Hunting with PEAK
  4. Model-Assisted Threat Hunting (M-ATH) with PEAK
  5. Turning Hunts Into Detections with PEAK
  6. Measuring Hunting Success with PEAK
  7. Threat Hunting Outcomes & Deliverables from PEAK

What’s a Threat Hunting Framework?

Before we dive into the world of PEAK, though, let's take a step back and talk about threat hunting frameworks in general.

A hunting framework is a system of repeatable processes designed to make your hunting expeditions both more reliable and more efficient. They help you understand:

With a trusty framework by your side, you're armed with a clear set of guidelines that can be tailored to your specific needs for each hunt. In essence, a framework provides repeatable processes and improves both the efficiency of your operations and the quality of your outputs.

While there are already a few frameworks out there — like the Sqrrl Threat Hunting Reference Model (which I helped create and was first published in 2015) and TaHiTI, created by the Dutch Payments Association in 2018 — they're starting to show their age. As our hunting programs continue to evolve, we need a framework that incorporates the additional experience and lessons we’ve learned in the last several years.

And that brings us to PEAK.

the-peak-threat-hunting-framework-collateral-cover-thumbnail

The PEAK Threat Hunting Framework

Download your complimentary copy of “The PEAK Threat Hunting Framework” to discover more about the framework.

/en_us/blog/fragments/forms/inline-form

The PEAK Framework: Threat Hunting, Modernized

PEAK, an acronym for "Prepare, Execute, and Act with Knowledge," brings a fresh perspective to threat hunting. It incorporates three distinct types of hunts:

Each PEAK hunt follows a three-stage process: Prepare, Execute, and Act. In the Prepare phase, hunters select topics, conduct research, and generally plan out their hunt. The Execute phase involves diving deep into data and analysis, while the Act phase focuses on documentation, automation, and communication. Crucially, each phase integrates Knowledge, which could be in the form of organizational or business expertise, threat intelligence, prior experience of the hunter(s), or of course, the findings from the current hunt.

Oh, and did we mention that PEAK is flexible like a cybersecurity ninja? We include detailed process diagrams and descriptions that show how most hunts of each type work to guide you while constructing your specific hunt. Hunters can skip, reorder, or add steps to each phase, tailoring their approach to suit the situation at hand.

Hypothesis-Driven Hunts

This is the classic approach, where hunters form a supposition about potential threats and their activities that may be present on the organization’s network, then use data and analysis to confirm or deny their suspicions.

Hypothesis-Driven Hunting Process in the PEAK Framework

➡️ Read our in-depth explainer of hypothesis-driven hunts in PEAK.

Baseline Hunts

In this type of hunt, hunters establish a baseline of “normal” behavior and then search for deviations that could signal malicious activity.

The Baseline Hunting Process in PEAK

➡️ Learn the who, what, where and why for baseline hunting with PEAK.

Model-Assisted Threat Hunts (M-ATH)

M-ATH hunts could be accurately described as "Sherlock Holmes meets artificial intelligence." Hunters use machine learning (ML) techniques to create models of known good or known malicious behavior and look for activity that deviates from or aligns with these models. Think of this as almost like a hybrid of the hypothesis-driven and baseline types, but with substantial automation from the ML.

Model-Assisted Threat Hunting (M-ATH) Process in PEAK

➡️ Get all the details on M-ATH in this dedicated tutorial.

PEAK Highlights

Now that you're acquainted with PEAK, you might be wondering what sets it apart from the crowd. Well, here are a few of its standout features:

Conclusion

In the ever-changing world of cybersecurity, staying ahead of the curve is crucial. The PEAK framework, with its unique blend of Hypothesis-Driven, Baseline, and Model-Assisted hunt types, provides a repeatable, flexible, and modern approach to threat hunting. As a result, organizations can defend against evolving threats more effectively than ever before.

So, there you have it — a preview of PEAK (you might even call it a “sneak PEAK”). Want to know more? Excellent, because we're just getting started! Explore the supporting articles, papers and other media diving deeper into the PEAK framework and threat hunting in general.

As always, security at Splunk is a family business. Credit to authors and collaborators: David Bianco, Ryan Fetterman

Related Articles

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends
Security
12 Minute Read

Predicting Cyber Fraud Through Real-World Events: Insights from Domain Registration Trends

By analyzing new domain registrations around major real-world events, researchers show how fraud campaigns take shape early, helping defenders spot threats before scams surface.
When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR
Security
4 Minute Read

When Your Fraud Detection Tool Doubles as a Wellness Check: The Unexpected Intersection of Security and HR

Behavioral analytics can spot fraud and burnout. With UEBA built into Splunk ES Premier, one data set helps security and HR reduce risk, retain talent, faster.
Splunk Security Content for Threat Detection & Response: November Recap
Security
1 Minute Read

Splunk Security Content for Threat Detection & Response: November Recap

Discover Splunk's November security content updates, featuring enhanced Castle RAT threat detection, UAC bypass analytics, and deeper insights for validating detections on research.splunk.com.
Security Staff Picks To Read This Month, Handpicked by Splunk Experts
Security
2 Minute Read

Security Staff Picks To Read This Month, Handpicked by Splunk Experts

Our Splunk security experts share their favorite reads of the month so you can follow the most interesting, news-worthy, and innovative stories coming from the wide world of cybersecurity.
Behind the Walls: Techniques and Tactics in Castle RAT Client Malware
Security
10 Minute Read

Behind the Walls: Techniques and Tactics in Castle RAT Client Malware

Uncover CastleRAT malware's techniques (TTPs) and learn how to build Splunk detections using MITRE ATT&CK. Protect your network from this advanced RAT.
AI for Humans: A Beginner’s Field Guide
Security
12 Minute Read

AI for Humans: A Beginner’s Field Guide

Unlock AI with the our beginner's field guide. Demystify LLMs, Generative AI, and Agentic AI, exploring their evolution and critical cybersecurity applications.
Splunk Security Content for Threat Detection & Response: November 2025 Update
Security
5 Minute Read

Splunk Security Content for Threat Detection & Response: November 2025 Update

Learn about the latest security content from Splunk.
Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It
Security
3 Minute Read

Operation Defend the North: What High-Pressure Cyber Exercises Teach Us About Resilience and How OneCisco Elevates It

The OneCisco approach is not about any single platform or toolset; it's about fusing visibility, analytics, and automation into a shared source of operational truth so that teams can act decisively, even in the fog of crisis.
Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy
Security
5 Minute Read

Data Fit for a Sovereign: How to Consider Sovereignty in Your Digital Resilience Strategy

Explore how digital sovereignty shapes resilient strategies for European organisations. Learn how to balance control, compliance, and agility in your data infrastructure with Cisco and Splunk’s flexible, secure solutions for the AI era.