Defense & MDRMedia / digital publishing3-week hunt, then ongoing MDR
A proactive threat hunt that evicted persistence before data left the building
Digital publishing group, ~600 staff, hybrid cloud and on-prem estate
No alert had fired. The publisher commissioned a hypothesis-driven threat hunt as an assurance exercise — and the hunt found a webshell on a forgotten staging server and credential-harvesting activity that existing tooling had been silently missing for weeks. Eviction ran as a coordinated action before any evidence of bulk data exfiltration appeared, and the telemetry gaps the attacker had lived in were closed under ongoing MDR.
Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.
- Alerts fired before the hunt
- 0
- activity lived entirely in telemetry blind spots
- Attacker activity window reconstructed
- ~5 weeks
- webshell to eviction
- Evidence of bulk exfiltration
- none found
- in the reconstructed window — caught at staging
- New detections from hunt findings
- 17
- now running under continuous MDR
The challenge
- The estate had grown through acquisitions into a hybrid sprawl where nobody could say with confidence 'we are not currently compromised.'
- Existing tooling alerted on known-bad signatures but had blind spots in exactly the places attackers prefer — forgotten servers and identity infrastructure.
- Leadership wanted evidence-based assurance, not another dashboard subscription.
What we did
- Ran structured hunts against explicit hypotheses: living-off-the-land activity in identity infrastructure, persistence on internet-facing legacy systems, and abnormal service-account behaviour.
- Swept the estate's forgotten edges — staging systems, acquisition-inherited servers and stale DNS — where inventory said nothing should be running.
- Confirmed a webshell and harvested-credential use, then mapped the activity's full extent before touching anything.
- Executed a coordinated eviction — simultaneous credential invalidation, host isolation and persistence removal — so the attacker had no partial-remediation warning.
- Converted every hunt finding into a detection rule and closed the telemetry gaps under the ongoing MDR service.
The outcome
- Active persistence and credential harvesting were found and evicted with no evidence of bulk data exfiltration in the reconstructed activity window.
- Every blind spot the attacker exploited now feeds the detection stack, with hunt hypotheses re-run on a standing cadence.
- Leadership's question changed from 'are we compromised?' to a monthly, evidence-backed answer.
“Zero alerts and an active intruder — that combination is exactly why we bought a hunt instead of another tool. They found what the stack couldn't see, then fixed the stack so it could.”