Threat Hunting Assessment Questionnaire
Use this questionnaire to assess your organization’s threat hunting readiness, visibility, and detection coverage.
Assessment Scope and Environment
Organization / Team Name
*
Primary Environment Being Assessed
*
Cloud
On-Premises
Hybrid
Endpoints
Identity
Network
Other
Assessment Scope / Notes
*
Threat Hunting Maturity and Preparedness
Threat hunting maturity level
*
Ad hoc
1
2
3
4
5
6
7
8
9
Optimized
10
1 is Ad hoc, 10 is Optimized
Rate the following statements
*
Rows
Strongly Disagree
Disagree
Neutral
Agree
Strongly Agree
We have adequate visibility across critical assets and environments
1
2
3
4
5
Logging coverage is sufficient to support threat hunting
6
7
8
9
10
Alert quality is high enough to minimize noise and false positives
11
12
13
14
15
Our investigation workflow is consistent and well documented
16
17
18
19
20
Overall visibility and telemetry quality
*
1
2
3
4
5
Investigation workflow effectiveness
*
Ineffective
1
2
3
4
5
6
7
8
9
Highly effective
10
1 is Ineffective, 10 is Highly effective
Detection, Data, and Response Coverage
Highest-priority threat categories to hunt for
*
Phishing and credential theft
Malware and ransomware
Lateral movement
Privilege escalation
Data exfiltration
Cloud account compromise
Insider threat
Command-and-control activity
Other
Telemetry and data sources available
*
Endpoint detection logs
Windows event logs
Linux system logs
Network flow data
DNS logs
Proxy / web gateway logs
Email security logs
Identity and authentication logs
Cloud audit logs
Firewall logs
VPN / remote access logs
SIEM correlations
Threat intelligence feeds
Other
Current tooling gaps, planned next steps, or support needed
Submit
Should be Empty: