In intelligence practice, there is a framework for categorizing what you know and do not know that I find more useful for thinking about security than most security-specific frameworks: known knowns, known unknowns, and unknown unknowns.
Known unknowns are uncomfortable but manageable. Unknown unknowns are dangerous precisely because they are invisible. The adversary who finds an unknown unknown in your environment - a path your detection doesn't watch, a technique your rules don't cover - has found a position of significant operational advantage.
| Threat Category | Operational Focus | Primary Defensive Mechanism | Strategic Limitation |
| Known Knowns | Expected TTPs & signatures | Static correlation rules & legacy SIEM | Fully reliant on pre-existing rule libraries |
| Known Unknowns | Identified telemetry gaps | Coverage gap analysis & log ingestion | Addresses known coverage, not novel tactics |
| Unknown Unknowns | Unanticipated attack paths | AI Threat Hunting | Requires exploratory machine analytics beyond static alerts |
Alert-based security operations cannot address unknown unknowns by definition. If no detection fires, no alert appears, no response is triggered. The unknown unknown persists, unobserved, for as long as the adversary chooses to operate in it.
Situational awareness is the operational capability that directly addresses unknown unknowns - and AI threat hunting is how modern security operations execute it at scale.
Executing an AI threat hunting strategy means not waiting for a static detection to fire. Instead, AI agents actively explore the environment - asking open-ended questions of the full telemetry record, recognizing subtle deviations that don't fit the established digital tone of the enterprise, and amplifying human analytical intuition into areas that formal rules overlook.
At Netenrich, some of the most significant security findings from our customers' environments - active intrusions in earlier kill-chain stages than detection would have surfaced, exposures creating serious risk before any adversary had exploited them - came from situational awareness work. Not from alerts. From analysts with the time, the tools, and the investigative orientation to look for what detection was not finding.
The unknown unknowns are findable. They require the right analytical foundation and the organizational discipline to protect the time to look for them.
Tired of relying on static SIEM rules that leave critical blind spots in your environment? Fast-track your security operations with Netenrich to equip your team with unified telemetry, entity-resolved context, and an AI-driven Agentic SOC.
*Part of my ongoing series on data science and the future of security operations.*