Why We Will Probably Always Need Human ‘Threat Hunters’ Back to Blog
Security

Why We Will Probably Always Need Human ‘Threat Hunters’

@Jeff Hamm March 9, 2026 5 mins

Close to midnight. Automated triage finished. Queue empty. Most of the team signed off. But a few scattered events didn't fit the rhythm of the environment. A login slightly earlier than usual. A process tree that was too tidy. Commands issued too close together. Nothing alarming on its own. The shape of them felt deliberate. Detection systems don't see that. People do.

It was close to midnight when the bridge went quiet. Automated triage had finished. The queue was empty. The detection timeline showed nothing urgent. Most of the team signed off, satisfied that the noise had settled. I stayed. A few scattered events did not fit the rhythm of the environment. They were not loud. They were not even marked as suspicious. They were just out of character. A login that was slightly earlier than usual. A process tree that was not wrong, only too tidy. A pair of commands issued too close together. Nothing in the set was alarming. The shape of them felt deliberate. These moments rarely show up in detection systems. They show up in people.

Years in incident response change how you see activity. You stop looking for alarms and start looking for behavior. That night, the behavior suggested a person who was testing boundaries quietly and adjusting in real time. It suggested someone who believed no one was watching. Automation could not see the pressure in the timing. Automation could not feel the tension between each action. These signals are human. It takes another human to see them.

The Nature of the Work Has Always Been Human

Threat detection and response are built on technical systems, but the work has always been human against human. Attackers bring habits, instincts, stress, and creativity into an environment. They make choices based on fear, time, opportunity, and confidence. They rush when they think defenders are close. They slow down when they believe the environment is unmonitored. They repeat mistakes because repetition is part of human nature.

Analysts study these patterns the way investigators study a suspect’s behavior. They learn the difference between exploration and execution. They recognize when an attacker is improvising. They notice hesitation. They understand when an operator is trying to blend in and when the operator has given up on stealth. These signals do not look like indicators of compromise. They look like human behavior expressed through system activity.

AI does not read behavior. It reads anomalies and correlations. Humans read intent.

Why AI Helps but Does Not Replace Analysts

AI accelerates the mechanical parts of the job. It organizes evidence. It reduces noise. It clusters similar artifacts. It predicts which leads might matter. These are real improvements. They make analysts more effective and reduce the fatigue that used to dominate the field.

What AI does not do is interpret meaning.

A model can identify an authentication spike. It cannot tell you that the spike represents hesitation. A system can surface an odd process chain. It cannot explain that the chain matches the operator’s earlier pattern of lateral discovery. AI can show you a cluster of unusual commands. It cannot tell you that the attacker was growing impatient.

These interpretations come from immersion in real investigations. They come from seeing hundreds of incidents and understanding the subtle differences between an attacker who is probing quietly and an attacker who is preparing to cause damage. AI shows evidence. Humans explain it.

What AI in IR Actually Is

Much of the industry uses the word “AI” as if it were a single capability. In practice, incident response tools rely on two very different kinds of technology. Detection engines use machine learning, behavioral models, and statistical scoring. These systems watch activity in real time and look for patterns that fall outside expected behavior. They are narrow and specialized. They do not understand context, but they are fast and consistent.

LLMs are something else entirely. They do not watch system activity. They do not detect intrusions. They do not decide whether an action is malicious. They take structured evidence from other systems and turn it into readable language. They help analysts interpret models, summarize alerts, and move through workflows more efficiently. They smooth the edges of complex tools so that analysts spend more time thinking and less time navigating interfaces.

Modern IR often blends these two capabilities. The detection engine runs first. The LLM sits on top to help explain the findings and guide the next steps. This pairing makes the work faster and more organized. It does not remove the analyst. It supports the analyst. The decision making still depends on someone who understands the environment, the attacker’s behavior, and the context that surrounds each action.

This distinction matters. When people talk about “AI replacing analysts,” they are usually describing systems that do not make decisions on their own. Detection systems still rely on human judgment. LLMs still rely on human review. Together they create a stronger workflow, but neither of them replaces the part of the job that requires interpretation. That part remains human.

CategoryMachine Learning (ML) - DetectsLarge Language Models (LLMs) - Interpret
RoleIdentifies patterns and anomalies based on defined featuresExplains patterns, relationships, and meaning using context
How it WorksUses structured signals (process ancestry, auth time, network behavior) to produce scores or labelsUses natural language reasoning to describe what evidence suggests and how pieces fit together
StrengthConsistent, fast detection when features are well-definedRich interpretation, contextualization, summarization
WeaknessCannot explain intent; limited to what it was trained to detectCannot perform detection; depends on ML or analyst-provided evidence
Primary Output“Suspicious / Not suspicious,” numeric risk, anomaly scoresNarrative explanations, hypotheses, context-aware guidance

Table 1: ML vs LLM (Condensed + Detection vs Interpretation Focus)

The Trap of Believing the Tools Are Enough

The industry has a habit of believing that each wave of technology will replace analysts. It happened with SIEM platforms. They promised automated correlation and continuous detection. They delivered alert fatigue and more complexity. It happened with early EDR tools. They promised visibility so strong that analysts would not need to investigate deeply. They delivered more data than anyone could review manually. It happened with incident automation. Playbooks were marketed as decision-makers. They became checklists that still required human oversight.

Now it is happening again with AI.

The claim is that systems will identify, classify, and respond without human involvement. The reality is that the moment an attacker chooses a novel path, or misuses a legitimate tool, or behaves unpredictably, the model loses context. Analysts do not. Analysts shift with the attacker because they understand the human behind the intrusion.

Tools evolve. Attackers evolve faster.

Where Humans Still Outperform Machines

Pattern sense

Years before I worked in cybersecurity, I learned how powerful pattern sense can be. I was a young sheriff’s deputy working midnight shift in a township I knew better than most people who lived there. I had delivered pizzas there since I was sixteen. I went to vocational school there. I even knew where Commerce Road and Commerce Road intersected and where one of the two met South Commerce Road. That intersection confused dispatchers and new deputies, but to me it was familiar ground.

One night a series of calls came in. Car windows shot out with a BB gun. Five reports in total. I did not handle any of them. The afternoon shift took the paperwork, and no cop is eager to write more than they have to. A BOLO went out, but we had nothing useful. No vehicle description. No witnesses with clear details. It was the type of case that usually goes nowhere.

I decided it was not going to go nowhere. I had the county’s first Tahoe patrol unit back then. I shut off all the lights, let my eyes adjust, and worked a quiet grid across the township. Rural roads. Sparse traffic. A pattern in my head of where someone would go if they wanted to do damage and avoid attention. That knowledge did not come from a manual. It came from living there.

A single car appeared on Commerce Road. Moving slowly at two in the morning. Stopping and starting in a way that was not drunk and not normal. Something in the rhythm was wrong. I rolled toward them. They paused at a stop sign before they noticed my approach. When I lit them up with overheads and takedowns, the truth was immediate. Two young men in the front seat. A BB gun in the passenger’s lap. The look in their eyes told me everything. They were arrested on the spot. And I had a long report to write.

That was hunting. Investigating without a lead. Moving on pattern, familiarity, and human behavior. It is the same foundation that strong incident responders rely on today.

Environmental context

Every organization has its own rhythm. Some environments rely on late-night administrative access. Others generate noisy internal traffic that would look malicious anywhere else. An analyst who understands the environment can spot the difference between a familiar oddity and an intrusion trying to blend in. AI sees deviation from a model. Analysts see deviation from lived experience.

Adversary empathy

Experienced analysts learn to recognize attacker emotion. Confidence looks different from confusion. A careful operator leaves a different trace than one who is frustrated. A rushed attacker has a signature of impatience. These are not technical patterns. They are human ones.

Scenario building

Machines collect evidence. Humans connect it. Analysts build timelines, evaluate motive, and decide what matters. They understand when an event is a pivot, when it is discovery, and when it is an attempt to recover access after losing it. They create meaning from fragments. Analysts create meaning from fragments and read an intruder’s progress in a way that technical signals alone cannot convey.

The Hardest Part for Machines: Understanding Pressure

Pressure changes everything in an intrusion. Attackers behave one way when they believe defenders are asleep. They behave another when they believe someone is close. They speed up. They skip steps. They misconfigure tools. They abandon stealth. All of these shifts are familiar to experienced responders. They are familiar because they are human.

Models do not understand pressure. Analysts do.

Humans at the Center of the AI Supported SOC

AI will eliminate much of the manual effort that used to slow down investigations. It will push analysts toward higher-value decisions. It will surface weak signals that once required hours of searching.

The analyst’s role will not disappear. It will increase.

Analysts will become interpreters of machine-assembled evidence. They will become the judgment layer. They will decide what matters and what does not. They will recognize when the environment is telling the truth and when the attacker is bluffing. AI cannot do that. It does not understand fear, risk, or intent.

The future SOC is not autonomous. It is augmented. It is faster, more structured, and more consistent. It still depends on human reasoning.

Bringing the Discipline Back Into Focus

The tools will evolve. The field will adopt new language. Workflows will shift. Through all of this, the work will remain rooted in the same skill it always demanded. The ability to recognize when something is off. The ability to understand behavior. The ability to read the human presence inside technical evidence.

Attackers are human. Defenders must remain human.

The strength of modern cybersecurity comes from the combination of fast systems and thoughtful analysts. AI improves the speed. Analysts provide the meaning.

Key Points (TL;DR)

About the Author

Jeff Hamm is the Managing Director of HammNet UG and founder of Evidenx and an independent global incident response leader. He specializes in digital forensics, ransomware recovery, cyber crisis management, and the application of AI-ML in cybersecurity.

[email protected]

#AI #Security
More Articles