Proactive threat hunting finds adverse activity that evades automated detection (new in v4.0). Partially achieved: required resources identified and deployable occasionally (for example after a tip-off), hunts follow documented hypothesis, data or entity driven methods, and hunts and follow-up analysis are documented. Achieved: hunting resources deployed as business as usual at a frequency matching the risk, structured methods, hunts turned into automated detections, records used to improve hunting and security, justified confidence in effectiveness with the process reviewed, automation used where suitable, and focus on attacker tactics, techniques and procedures rather than atomic indicators.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.