Skip to content
Solvex Space
Defense & MDRMedia / digital publishing3-week hunt, then ongoing MDR

A proactive threat hunt that evicted persistence before data left the building

Digital publishing group, ~600 staff, hybrid cloud and on-prem estate

No alert had fired. The publisher commissioned a hypothesis-driven threat hunt as an assurance exercise — and the hunt found a webshell on a forgotten staging server and credential-harvesting activity that existing tooling had been silently missing for weeks. Eviction ran as a coordinated action before any evidence of bulk data exfiltration appeared, and the telemetry gaps the attacker had lived in were closed under ongoing MDR.

Representative engagement — the client is confidential, and the figures and the quoted comment illustrate typical outcomes for the work described.

Alerts fired before the hunt
0
activity lived entirely in telemetry blind spots
Attacker activity window reconstructed
~5 weeks
webshell to eviction
Evidence of bulk exfiltration
none found
in the reconstructed window — caught at staging
New detections from hunt findings
17
now running under continuous MDR

The challenge

  • The estate had grown through acquisitions into a hybrid sprawl where nobody could say with confidence 'we are not currently compromised.'
  • Existing tooling alerted on known-bad signatures but had blind spots in exactly the places attackers prefer — forgotten servers and identity infrastructure.
  • Leadership wanted evidence-based assurance, not another dashboard subscription.

What we did

  • Ran structured hunts against explicit hypotheses: living-off-the-land activity in identity infrastructure, persistence on internet-facing legacy systems, and abnormal service-account behaviour.
  • Swept the estate's forgotten edges — staging systems, acquisition-inherited servers and stale DNS — where inventory said nothing should be running.
  • Confirmed a webshell and harvested-credential use, then mapped the activity's full extent before touching anything.
  • Executed a coordinated eviction — simultaneous credential invalidation, host isolation and persistence removal — so the attacker had no partial-remediation warning.
  • Converted every hunt finding into a detection rule and closed the telemetry gaps under the ongoing MDR service.

The outcome

  • Active persistence and credential harvesting were found and evicted with no evidence of bulk data exfiltration in the reconstructed activity window.
  • Every blind spot the attacker exploited now feeds the detection stack, with hunt hypotheses re-run on a standing cadence.
  • Leadership's question changed from 'are we compromised?' to a monthly, evidence-backed answer.
Zero alerts and an active intruder — that combination is exactly why we bought a hunt instead of another tool. They found what the stack couldn't see, then fixed the stack so it could.
IT Director, digital publishing groupIllustrative — composed to show the kind of feedback this work draws, not a quotation from a named client.
Proactive Threat Hunt & Eviction | Case Study — Solvex Space