Scopes of threat hunts
The scope or the size of the threat hunt is based upon realistic constraints and restraints that exist for the situation.
Definitions
Constraint: A limitation or restriction put on by an outside force or entity. This includes those by higher-level organizations and legal or regulatory authorities.
Restraint: A limitation or restriction put on by an internal force or entity. These include restraints from internal organizational stakeholders and policy, or the hunt team.
Limited resources
Time, equipment, personnel, access. All of these things will factor into how much can be accomplished in accordance with the business requirements of the organization.
Network size
Narrow, targeted scopes are needed for larger networks. If a team is hunting across 1 million node networks without sensors predeployed across the enterprise, a good portion of their time might be spent deploying and tuning the equipment. So, plan accordingly.