Threat hunting, like incident response, is a process-driven exercise. There is not a clearly defined and accepted process in place, but there is a general sequence that threat hunting takes that provides a process that can be followed. The following screenshot combines the various stages of a threat hunt into a process that guides threat hunters through the various activities to facilitate an accurate and complete hunt:
![](https://static.packt-cdn.com/products/9781838649005/graphics/assets/d778656a-bcbd-4e1e-9dba-0d4f951665c6.png)
Let's begin with the first stage.