Skip to content

Cybersecurity

OT threat hunting: chasing threats when the SOC and alerts are not enough

Reactive monitoring waits for an alert to fire. Threat hunting goes looking for the attacker the alerts never saw. How to apply threat hunting to OT environments, and why finding nothing is a good result.

3 min read

Beyond reactive monitoring

Most OT security programs, as they mature, reach monitoring: passive sensors, a detection platform, alerts feeding into a SOC. It is a major step forward compared to total darkness. But it has a structural limit: it only detects what has been defined as anomalous or malicious in advance. A patient attacker, moving slowly and using legitimate tools, can stay below the alert threshold for months.

Threat hunting exists to cover this space. It is the proactive activity of those who start from an uncomfortable assumption: the attacker may already be inside, and our alerts have not seen them. From there, you go looking for them in the data.

Hunting by hypothesis

Threat hunting is not staring at screens hoping to notice something. It is a structured method that starts from a hypothesis.

A hypothesis is a testable statement about an attacker's behavior. For example: "if an adversary had compromised an engineering workstation, they would use it to establish communications toward a PLC outside maintenance windows". From this hypothesis follows what to look for in the data: connections toward PLCs, correlated with maintenance schedules, originating from workstations that normally do not do so.

Hypotheses come from three main sources:

  • Threat intelligence: the known techniques of the groups that target the sector. "Sandworm uses this procedure, here is how we would look for it."
  • Knowledge of the environment: the plant's known weak points, the operational shortcuts, the connections that should not exist.
  • Weak anomalies: signals below the alert threshold that, taken individually, do not fire, but that deserve a targeted investigation.

MITRE ATT&CK for ICS as a map

Hunting in OT has a dedicated map: MITRE ATT&CK for ICS, the catalog of tactics and techniques specific to industrial environments. It is the ideal tool for generating systematic hypotheses instead of relying on intuition.

You start from a documented technique (for example the unauthorized modification of a controller's logic), translate it into an investigative question (what traces would it leave in the traffic or the logs?) and go to verify it in the collected data. By progressively covering the techniques relevant to your sector, you build a hunting program with measurable coverage, not an episodic one.

The differences compared to IT

Threat hunting in OT inherits the method from IT but changes profoundly in its constraints.

No intrusiveness. In IT you can query endpoints, run queries on agents, collect artifacts from live systems. In OT you cannot: scanning or probing a PLC can degrade its operation. Hunting relies exclusively on data collected passively, analyzed out of band.

The baseline is more stable. This is the advantage of OT. An industrial network is repetitive and predictable: the same devices speaking the same protocols at the same cadence. A solid behavioral baseline makes deviations far more evident than in the chaos of an IT network.

Operational context is everything. An anomalous connection may be an attacker or a technician carrying out extraordinary maintenance. The OT hunter must know the process to tell the difference, and this requires working closely with those who run the plant.

Why finding nothing is a good result

A hunt that ends without discovering any compromise is not wasted time. It produces two valuable outcomes.

The first is confidence: every hypothesis verified and discarded reduces the uncertainty about the real state of the environment.

The second, more important, is proof of visibility. During the hunt you constantly ask yourself: if the attacker had really been here, would we have found them in our data? When the answer is no, the hunt has revealed a blind spot to close, a missing data source, a poorly positioned sensor. In this sense every hunt strengthens the defenses regardless of the outcome, and threat hunting becomes the engine that makes monitoring evolve instead of leaving it static.

The MON5 angle

Hunting by hypothesis requires data against which to test them: without a baseline of OT traffic and a history of communications, every hunt stops at the first question. MON5 collects this data passively and out of band, directly on the native industrial protocols (Modbus, Siemens S7, OPC UA, PROFINET, EtherNet/IP), without querying the control devices.

The platform's PROTECT phase pairs ML anomaly detection with a continuous behavioral baseline: the raw material on which to build hypotheses, verify them and discover the blind spots in visibility. If you do not yet know what your OT network would let you see, an OT assessment is the place to start.

Analysis and commentary by MON5 based on public-domain research and data from the OT/ICS sector.

OTthreat huntingdetectionMITRE ATT&CKSOC

Related articles

OT network traffic baseline chart with anomalous deviations highlighted and a maintenance-window calendar

Cybersecurity

Anomaly detection in OT: building the baseline and managing false positives

OT networks are repetitive and predictable, in theory the ideal environment for anomaly detection. In practice, legitimate-but-anomalous behavior generates a false-positive noise that is the main cause of failure for industrial monitoring projects.

5 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna