ASD ISM 2153Quarterly Threat Hunting Informed by Current Threat Intelligence
At least every three months, actively search your systems for hidden intruders, guided by up-to-date strategic and sector-specific cyber threat intelligence.
Plain language
Threat hunting is the practice of going looking for attackers who may already be inside your environment, rather than waiting for an alert to fire. Automated tools only catch what they have been told to look for. Capable adversaries deliberately stay below those thresholds, using legitimate accounts and built-in tools so that nothing obviously trips. A hunt starts from a hypothesis (for example, "an attacker targeting our sector is known to abuse remote management tools; is there any sign of that here?") and then checks logs, endpoints and network data for evidence. This control requires two things. First, the hunts must be informed by current cyber threat intelligence at two levels: strategic intelligence (the broad picture of who is targeting Australian organisations and why) and sector-specific intelligence (what adversaries are doing against organisations like yours right now). That focus stops hunting from becoming a random trawl and points it at the techniques most likely to be used against you. Second, hunts must happen at least every three months, so that the gap between an intrusion and its discovery is bounded rather than open-ended. Why it matters: intrusions frequently go undetected for months. Every extra week an attacker spends inside is more data exfiltrated, more persistence established and a harder clean-up. Regular, intelligence-led hunting shortens that dwell time and finds the quiet compromises that monitoring alone misses.
Framework
ASD Information Security Manual (ISM)
Control effect
Detective
Classifications
NC, OS, P, S, TS
ISM last updated
Sept 2026
Control Stack last updated
05 Sept 2026
E8 maturity levels
N/A
Official control statement
Threat hunting activities, informed by current strategic and sector-specific cyber threat intelligence, are conducted at least every three months.
Why it matters
Without regular, intelligence-informed threat hunting, an adversary who has evaded automated detection can remain in your environment indefinitely. Detection then depends on luck, an external notification or the attacker choosing to act (for example, deploying ransomware or leaking data). Hunts that are not informed by current strategic and sector-specific intelligence waste effort on unlikely scenarios while missing the techniques actually being used against your sector, and hunts that lapse beyond three months leave long windows in which a compromise can mature undetected.
Operational notes
In practice this control runs as a recurring cycle. Before each hunt, the team reviews current strategic and sector-specific threat intelligence (for example, national cyber security advisories, sector information-sharing group reports and vendor intelligence relevant to your industry) and converts it into a small number of testable hypotheses about attacker techniques. During the hunt, analysts query available telemetry (endpoint, identity, network and application logs) for evidence matching those hypotheses, and any suspicious finding is handed to incident response. After the hunt, findings, confirmed or negative, are documented, and useful queries are turned into ongoing detections so future hunts can move to new ground.
Keep the schedule visible: a calendar entry or ticket for each quarter, with an owner, prevents the "at least every three months" requirement from slipping when other work gets busy. Record the intelligence sources used for each hunt so it is clear the activity was informed by current intelligence rather than a standing checklist. Smaller organisations without in-house analysts can meet the control through a managed security provider, provided the provider's hunts are intelligence-informed, sector-relevant and demonstrably conducted at least quarterly.
Implementation tips
- The security manager establishes a threat hunting schedule with a hunt booked at least every three months, assigns a named lead for each hunt, and tracks each one in the team's work management tool so the quarterly cadence is never missed.
- The threat intelligence lead (or the security manager in a smaller team) subscribes to and reviews current strategic and sector-specific intelligence sources, such as national cyber security advisories and industry information-sharing group reports, and summarises the relevant adversary techniques before each hunt.
- The hunt lead turns that intelligence summary into three to five written hypotheses for the quarter, each naming the technique being hunted, the data source to be checked and the query or method that will be used.
- Security analysts run the hunt by executing the planned queries across endpoint, identity and network telemetry, investigate any hits, and escalate confirmed suspicious activity to the incident response process straight away.
- The hunt lead writes up each hunt with the intelligence sources used, hypotheses tested, results and follow-up actions, and works with the detection engineering owner to convert productive queries into permanent monitoring rules.
Audit / evidence tips
- AskAsk for the threat hunting schedule and records of hunts completed over the past twelve months.Look atCheck the dates of completed hunts and the gaps between them.GoodHunts have been conducted with no more than three months between any two, and each has a named owner and completion record.
- AskAsk for the threat intelligence inputs used to plan the most recent hunt.Look atConfirm the sources are current and include both strategic intelligence and intelligence specific to the organisation's sector.GoodThe hunt plan cites recent advisories and sector-specific reporting, dated close to the hunt, rather than a generic or stale threat list.
- AskAsk for the hunt hypotheses or plan for a recent quarter.Look atTrace each hypothesis back to the threat intelligence that prompted it.GoodEach hypothesis names a specific adversary technique drawn from the cited intelligence, the data to be searched and the method used.
- AskAsk for the outputs of a recent hunt, such as analyst notes, saved queries or tool exports.Look atLook for evidence that the planned queries were actually run against real telemetry and that results were reviewed.GoodQuery results, timestamps and analyst commentary show the hunt was performed as planned, including negative results being recorded.
- AskAsk for the hunt report and any actions raised from the last two hunts.Look atCheck whether findings were escalated to incident response where warranted and whether useful queries became ongoing detections.GoodReports document results and follow-up, with evidence that confirmed findings were handled as incidents and lessons were fed back into monitoring.
Cross-framework mappings
How ISM-2153 relates to controls across ISO/IEC 27001, ISO/IEC 42001, Essential Eight, and ASD ISM.
ISO 27001
| Control | Notes | Details |
|---|---|---|
handshakeSupports(2)expand_less | ||
| Annex A 8.15 | ISM-2153 requires quarterly threat hunting informed by threat intelligence to actively search for hidden intruders | |
| Annex A 8.16 | ISM-2153 requires quarterly threat hunting that is informed by current strategic and sector-specific cyber threat intelligence | |
extensionDepends on(1)expand_less | ||
| Annex A 5.7 | ISM-2153 mandates quarterly threat hunting to be informed by current cyber threat intelligence | |
These mappings show relationships between controls across frameworks. They do not imply full equivalence or certification.
Related ASD ISM controls in Security assurance
See all Guidelines for security assurance controls, or browse the full ASD ISM library.