The organisation establishes and maintains a cyber threat hunting capability to search for indicators of compromise and to detect, track and disrupt threats that evade existing controls, and uses it at a set frequency. No enhancements.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.