Communicating with other administrators
The day-to-day organizational defenders, administrators, and users will be operating on the network at the same time as the threat hunting team. Ensuring open communications will be crucial in order to prevent duplication of effort or friendly fire against legitimate users or systems. Include these other members as part of the team from day 1. If possible, allow them access to the same communication channels as the team. If the hunt team and administrators are located in the same area, attempt to forge professional relationships through non-work-related discussions.
Another avenue to pursue with day-to-day administrators is to make communication deliberate. After the daily check-in discussion with the team, set time aside to physically engage, if possible, with the other administrators to see whether they've noticed anything in order to continue to build that relationship. The local administrators will remember things during the engagement...