Threat Hunters actively search for malicious activity that has bypassed traditional defenses. Instead
of waiting for alerts, they analyze logs, endpoint telemetry, and network traffic to uncover hidden
attackers. They investigate anomalies, develop detections, and map activities to frameworks such as
MITRE ATT&CK. This role combines incident response, malware analysis, and forensic investigation.