Connecting the dots
So basically, we have now had an overview of the two main types of security controls that we have in our arsenal: prevention and detection (threat hunting falling into the latter). A simplified approach to define whether we have to use one of them could be designed using the following workflow:
As said, prevention is ideal, but it's not always feasible in a production environment or it might take a strong amount of effort to mitigate a limited risk. The first assessment should be whether our organization can implement a preventive measure. If that's not the case and we have sufficient information that is detailed enough to build a confident detection rule, then we should go for automated detection alerting.
However, when we are at the result count assessment, if it goes over the predefined threshold we have defined (which corresponds to our capabilities...