Netenrich Blog | Expert Cybersecurity Insights on SecOps, threats & more

AI Threat Hunting: Uncovering the Unknown Unknowns

Written by Raju Chekuri | Tue, Oct 06, 2026 @ 10:11 AM

In intelligence practice, there is a framework for categorizing what you know and do not know that I find more useful for thinking about security than most security-specific frameworks: known knowns, known unknowns, and unknown unknowns.

  • Known knowns: The threats your detection architecture was built to find. When these appear, your tools surface them. Your team has playbooks for them. This is where most security investment is focused and most security value is produced daily.
  • Known unknowns: The gaps you are aware of. The adversary techniques in your threat model that you haven't built detection coverage for yet. The data sources you know you're not collecting. The attack surfaces you know you're not monitoring. These are addressable through systematic coverage gap analysis and remediation - the work of looking at your detection architecture against a threat framework and closing the gaps.
  • Unknown unknowns: The threats you don't know you're not seeing. Novel techniques that have not yet appeared in public threat intelligence. Attack paths through your specific environment that your security architecture did not anticipate when it was designed. Adversary activity that generates no signal in your current detection infrastructure because it doesn't match any pattern your detection logic looks for.

Known unknowns are uncomfortable but manageable. Unknown unknowns are dangerous precisely because they are invisible. The adversary who finds an unknown unknown in your environment - a path your detection doesn't watch, a technique your rules don't cover - has found a position of significant operational advantage.

Categorizing Enterprise Threat Visibility

Threat Category Operational Focus Primary Defensive Mechanism Strategic Limitation
Known Knowns Expected TTPs & signatures Static correlation rules & legacy SIEM Fully reliant on pre-existing rule libraries
Known Unknowns Identified telemetry gaps Coverage gap analysis & log ingestion Addresses known coverage, not novel tactics
Unknown Unknowns Unanticipated attack paths AI Threat Hunting Requires exploratory machine analytics beyond static alerts


Why Alert-Based Security Operations Fall Short

Alert-based security operations cannot address unknown unknowns by definition. If no detection fires, no alert appears, no response is triggered. The unknown unknown persists, unobserved, for as long as the adversary chooses to operate in it.


Situational Awareness Through AI Threat Hunting

Situational awareness is the operational capability that directly addresses unknown unknowns - and AI threat hunting is how modern security operations execute it at scale.

Executing an AI threat hunting strategy means not waiting for a static detection to fire. Instead, AI agents actively explore the environment - asking open-ended questions of the full telemetry record, recognizing subtle deviations that don't fit the established digital tone of the enterprise, and amplifying human analytical intuition into areas that formal rules overlook.

At Netenrich, some of the most significant security findings from our customers' environments - active intrusions in earlier kill-chain stages than detection would have surfaced, exposures creating serious risk before any adversary had exploited them - came from situational awareness work. Not from alerts. From analysts with the time, the tools, and the investigative orientation to look for what detection was not finding.

The unknown unknowns are findable. They require the right analytical foundation and the organizational discipline to protect the time to look for them.

Modernize Your SOC with AI Threat Hunting

Tired of relying on static SIEM rules that leave critical blind spots in your environment? Fast-track your security operations with Netenrich to equip your team with unified telemetry, entity-resolved context, and an AI-driven Agentic SOC.

*Part of my ongoing series on data science and the future of security operations.*

 
About the Author 


 

Raju Chekuri

A serial Silicon Valley entrepreneur and technology leader, Raju founded Netenrich and leads the company as chairman, president and CEO. Previously, he founded Velio Communications, Inc., and led its acquisition by LSI Logic and Rambus. He also served as chairman of the board at OpsRamp before it was acquired by HPE. He currently serves as an investor and advisor at early-stage startups Two Brothers Organic Farms and the Department of Lore. Raju earned an MBA at St. Mary’s College of California and a Bachelor of Technology at Kakatiya University.

Follow Raju on LinkedIn