
Security teams gain sharper threat hunts when their telemetry is clean, complete, and easy to query, and the SANS 2026 Threat Hunting Survey shows how far most programs still sit from that ideal. Half of the professionals surveyed named data quality or quantity as the biggest barrier to effective threat hunting, ahead of staffing, tooling, or process. The same respondents pointed to gaps in cloud logging and identity telemetry as the most common blind spots.
Patchy logs make it nearly impossible to spot attackers who blend in with normal administrative activity. A hunt built on incomplete telemetry tends to flag noise while a real intrusion slips past unnoticed.
What does the SANS 2026 survey say about data quality?
Data sits at the top of the list of obstacles. Fifty percent of respondents pointed to it as the single biggest barrier to effective hunting, more than any other factor the survey asked about. The specific gaps that came up most often were in cloud infrastructure logs and identity telemetry, the streams defenders need most when chasing attackers who move through valid credentials and cloud control planes.
Respondents also flagged evidence retention windows and log integrity as concerns, both of which shape how useful a historical record can be during an investigation. Collecting data at scale, without losing fidelity or context, was named as a related challenge.
Why do gaps in logging hurt against today’s attackers?
The attackers respondents reported seeing most often blend in with legitimate activity. Nation-state actors living off the land topped the list, with organized crime running the same technique and ransomware gangs close behind. Living off the land means using the tools already installed on a system, the same binaries an administrator would use, which makes signature-based detection useless.
Hunts against this kind of adversary have to target behavior: a legitimate tool doing something it should not, or data leaving by an unusual route. Each of those checks depends on telemetry the team may not have. Build a baseline of normal from patchy or inconsistent logs and the hunt starts raising false alarms while the real intrusion moves quietly through the environment.
Which environment is hardest to hunt in?
Cloud infrastructure. A third of respondents named it the hardest environment to hunt in, ahead of every other category the survey listed. That share has eased only slightly since the previous year’s survey, even as organizations continue to push more of their workloads and identity systems into cloud platforms.
The gap matters because cloud workloads generate telemetry that looks different from traditional on-premises logs, and identity providers produce their own streams that have to be correlated with the rest. Teams that built their hunting program around endpoint and network data often find the cloud pieces missing or under-collected.
Are teams using a formal hunting methodology?
Fewer than four in ten. Only 37% of programs now follow a formally defined hunting methodology, with ad hoc hunting slightly more common than the year before. Short staffing is the most likely reason: a team short on analysts runs whichever hunt its free person can handle that week, rather than working through a documented cycle.
That pattern leaves institutional knowledge inside one analyst’s head. When that person leaves, the program loses both the playbook and the muscle memory of running it. Published frameworks such as PEAK and TaHiTI give teams a repeatable structure without forcing them to design a methodology from scratch, and the survey points to them as a starting point for teams that want to standardize.
Are programs measuring whether hunts work?
Less often than two years ago. Just 40% of programs formally measure whether their hunts work, down from 64% in 2024. Reported outcomes have also shrunk: only 11% say hunting improved their security by 50% or more over the past year, compared with 47% in 2022.
The survey notes it cannot tell whether hunting is delivering less, whether respondents are grading themselves harder, or whether teams that stopped measuring also stopped noticing results. The likely explanation from the survey’s author is the last one: you tend to find less when you are not looking for it. The practical consequence is straightforward. A team that cannot show what its hunts found has little to bring to a budget meeting, and a program without measurement is harder to defend when leadership asks for return on investment.
Is AI fixing the gap?
Not yet, and fewer teams are even planning to add it. A third of respondents listed adding AI or machine learning to their hunting tools as a planned improvement, down from 48% in 2025. The drop could mean teams have moved from planning to implementation, or that they have taken a harder look at what these tools deliver day to day. The survey cannot say which.
Early free-text responses describe agentic hunting frameworks that keep human analysts making the calls, with AI used to narrow the field rather than to drive investigations on its own.
What should defenders take from the survey?
Three concrete priorities stand out. First, fix the data: closing the cloud logging and identity telemetry gaps gives every other part of the program something to work with. Second, adopt a published hunting framework such as PEAK or TaHiTI so the program survives staffing changes. Third, keep measuring. A hunting program that tracks outcomes can show what it found, defend its budget, and spot when a hunt has stopped producing value.
Teams that measure can show where threat-hunting delivers value and where it falls short, while teams without metrics struggle to justify their budget.
FAQ
What is the biggest barrier to effective threat hunting according to the SANS 2026 survey?
Data quality or quantity. Half of respondents named it as the single biggest barrier to effective threat hunting, ahead of staffing, tooling, or process.
Which environment do threat hunters find hardest to work in?
Cloud infrastructure. A third of respondents named it the hardest environment to hunt in, a share that has eased only slightly since the previous year’s survey.
How many threat hunting programs use a formal methodology?
Only 37%. Ad hoc hunting is now slightly more common, with short staffing cited as the likely reason programs have drifted away from a documented methodology.
This article summarizes reporting from helpnetsecurity.com.
