Uploaded June 2026 | Updated September 2026, 3 weeks ago
Starting an investigation---be it for troubleshooting, problem diagnosis, threat hunting, incident response, and so on---is fairly straightforward. There's a question or thesis you're pursuing, you have logs and data sources to check, and you have tools to deploy.
But if you don't find anything, does that mean there was nothing to find? Are you sure there was nothing? How much more time should you spend?
On today's Packet Protector we talk with Sydney Marrone. She works in detection engineering and threat hunting, and she wrote an insightful blog called When to Stop Hunting: The Art of Knowing You’ve Looked Hard Enough. This post lays out a detailed and defensible framework for how to decide enough's enough. While it's geared toward threat hunting, Drew and JJ also see parallels in the framework for network troubleshooting and other jobs that could go on forever if you let them.
Sydney is a cybersecurity professional, co-founder of THOR Collective, and co-author of the PEAK Threat Hunting Framework. She's a proud thrunter, community builder, and creator.
PP112
Links:
When to Stop Hunting: The Art of Knowing You’ve Looked Hard Enough - dispatch.thorcollective.com/p/when-to-stop-hunting
Sydney Marrone on LinkedIn - linkedin.com/in/sydneymarrone
THOR Collective - dispatch.thorcollective.com
The Agentic Threat Hunting Framework - nebulock.io/blog/agentic-threat-hunting-framework
Packet Protector is part of the Packet Pushers network. Visit our website to find more great networking and technology podcasts, along with tutorial videos, the Human Infrastructure newsletter, and loads more resources for building your IT career. packetpushers.net
Starting an investigation---be it for troubleshooting, problem diagnosis, threat hunting, incident response, and so on---is fairly straightforward. There's a question or thesis you're pursuing, you have logs and data sources to check, and you have tools to deploy.
But if you don't find anything, does that mean there was nothing to find? Are you sure there was nothing? How much more time should you spend?
On today's Packet Protector we talk with Sydney Marrone. She works in detection engineering and threat hunting, and she wrote an insightful blog called When to Stop Hunting: The Art of Knowing You’ve Looked Hard Enough. This post lays out a detailed and defensible framework for how to decide enough's enough. While it's geared toward threat hunting, Drew and JJ also see parallels in the framework for network troubleshooting and other jobs that could go on forever if you let them.
Sydney is a cybersecurity professional, co-founder of THOR Collective, and co-author of the PEAK Threat Hunting Framework. She's a proud thrunter, community builder, and creator.
PP112
Links:
When to Stop Hunting: The Art of Knowing You’ve Looked Hard Enough - dispatch.thorcollective.com/p/when-to-stop-hunting
Sydney Marrone on LinkedIn - linkedin.com/in/sydneymarrone
THOR Collective - dispatch.thorcollective.com
The Agentic Threat Hunting Framework - nebulock.io/blog/agentic-threat-hunting-framework
Packet Protector is part of the Packet Pushers network. Visit our website to find more great networking and technology podcasts, along with tutorial videos, the Human Infrastructure newsletter, and loads more resources for building your IT career. packetpushers.net










