Finding everything or nothing
Whether or not an analyst ends up finding the golden nugget that is an adversary at all is not proof of a successful threat hunt. This is due to the fact that a lack of evidence of identifiable adversary activity is not proof of no adversary being present. The focus should be kept on the hypothesis while noting items of interest for the customer to follow up with. Completion of objectives and tasks along with efficiency and their completeness are the best measurements of the team's success.