Threat Hunting Across Vendors
Threat Hunt Active. CI/CD Pipeline Not in Scope. Attacker Pivoted There.
5 min read · 18 May 2026 · Security
A software development vendor's security team initiated a proactive threat hunt following intelligence from a threat intelligence feed indicating that a specific threat actor group was targeting software development companies in their sector. The hunt was scope-defined to their highest-risk environments: the primary cloud infrastructure, the corporate network, and the code repositories. The three-week hunt identified and removed indicators of compromise from two systems and determined with reasonable confidence that the primary environment was clean. The threat hunt had not covered the vendor's SaaS-based customer success platform , a separate environment used for customer communication and tracking , and had not included the CI/CD pipeline's third-party components in the hunt scope. The threat actor group the intelligence had identified was specifically known for supply chain attacks targeting CI/CD pipelines as their initial insertion vector. The intelligence that triggered the hunt had specifically referenced CI/CD as a high-value target for this actor. The hunt scope excluded CI/CD. Six weeks after the hunt concluded with a clean-environment determination, a compromise of the vendor's CI/CD pipeline was identified , consistent with the tactics of the same threat actor group. The threat hunt had found a clean environment in the scope it investigated. The actor had been operating in the scope it excluded.
What is the Threat Hunting Across Vendors Problem, Really?
Threat hunting is the proactive, hypothesis-driven search for attacker activity in an environment , searching for indicators of compromise that automated detection has not flagged, based on threat intelligence about specific attacker techniques, known attacker behaviours, or anomaly patterns consistent with malicious activity. Effective threat hunting requires matching hunt scope to the attacker's known methodology: if intelligence indicates an actor targets CI/CD pipelines, the hunt scope must include CI/CD pipelines.
The hunt scope limitation problem arises when threat hunt scope is defined by what is easiest to hunt rather than what the triggering intelligence identifies as the actor's likely attack surface. Primary cloud environments and corporate networks are often well-instrumented with rich telemetry that makes them easier to hunt effectively. CI/CD pipelines, SaaS platforms, contractor access environments, and managed services may have limited telemetry, different log formats, and less mature tooling that makes them harder to include in hunt scope. Threat hunters who scope hunts to the environments they can investigate efficiently may inadvertently exclude the environments the specific attacker is most likely to be operating in.
The intelligence-to-scope alignment problem is the specific failure. A threat hunt triggered by intelligence about a specific threat actor group should be scoped to cover the environments and techniques that actor uses , derived from the intelligence about the actor's known methodology, preferred targets, and typical attack patterns. A hunt that is triggered by CI/CD-targeting actor intelligence but excludes CI/CD from scope has not matched the hunt to the intelligence. The hunt may confirm that the environments it covers are clean. It provides no assurance about the environments it did not cover.
- Hunt scope not matching intelligence-identified attack surface , CI/CD actor, non-CI/CD scope
- Scope defined by huntability rather than threat actor methodology
- CI/CD pipeline excluded from supply chain-relevant hunts
- SaaS platforms not included in threat hunt scope
- Contractor access environment not covered by hunt
Why this matters
Threat hunting across vendor environments matters for TPRM because sophisticated supply chain attackers specifically target the environments that are most likely to be out of scope for standard threat hunts , the CI/CD pipeline, the development environment, the contractor access system, and the managed services. A vendor who conducts proactive threat hunting on their primary environment provides genuine proactive security for those systems. If the hunt scope consistently excludes the environments supply chain attackers target, the hunting programme provides false confidence while leaving the highest-risk environments uninvestigated.
Where most teams get this wrong
The most consistent failure is accepting threat hunting activity as evidence of proactive security without asking whether the hunt scope matches the relevant threat actor methodologies. Hunt frequency and hunt activity describe programme operation. Hunt scope and intelligence alignment describe whether the programme addresses the relevant threats.
- Hunt activity accepted without scope assessment
- No intelligence-to-scope alignment verification
- CI/CD and development environments excluded from vendor threat hunt scope
- Hunt scope consistency not evaluated across hunts
- Supply chain specific hunt methodology not assessed
What good looks like
Mature threat hunting programmes align hunt scope to intelligence-identified threat actor methodology , specifically including CI/CD pipelines, development environments, and contractor access systems in hunts triggered by supply chain-targeting actor intelligence.
- Intelligence-aligned scope , hunt scope derived from threat actor's known methodology
- CI/CD pipeline hunting included in supply chain-relevant hunts
- Development environment coverage in threat hunts relevant to software supply chain
- Regular hunt cadence across full environment including hard-to-hunt systems
- Hunt scope documentation , explicit record of what was included and excluded
Tooling
Threat Hunting , Velociraptor, Osquery, CrowdStrike Falcon
Endpoint detection and response platforms with threat hunting capabilities provide the telemetry and query infrastructure for investigating specific hypotheses across endpoints and servers. For TPRM practitioners, asking whether the vendor's threat hunting extends to CI/CD pipeline hosts and development environment servers , the specific environments that supply chain actors target , provides a specific scope question.
CI/CD Security , Legit Security, Argon, GitHub Advanced Security
Supply chain security platforms specifically designed for CI/CD environments provide the telemetry and threat hunting infrastructure for pipeline-focused investigations. For TPRM practitioners, asking whether the vendor uses dedicated CI/CD security tooling that would support threat hunting in pipeline environments provides a specific supply chain hunting capability question.
Governance challenges
The governance challenge with threat hunting scope is the telemetry availability problem. Threat hunting requires rich telemetry , detailed logs, process execution records, network connections, and file system events. Environments with limited telemetry are difficult to hunt effectively. The governance resolution is building telemetry into the environments most likely to be targeted before the hunt is required.
- Ask for most recent hunt scope , what environments were included
- Ask whether CI/CD was included in supply chain-relevant hunts
- Ask how hunt scope is derived from triggering intelligence
- Ask for CI/CD specific security tooling deployment
- Ask for hunt findings summary , what was found and what was cleared
If you are a small team
For your highest-risk software vendors , those delivering software into your environment , ask one question about their most recent threat hunt: was the CI/CD pipeline and build environment included in the hunt scope? If the answer is no, ask why not. For supply chain attackers specifically targeting the build pipeline, a threat hunt that excludes the build pipeline provides no assurance about the specific systems the actor targets. The intelligence that triggered the hunt defines the scope the hunt should cover.
- Ask whether CI/CD was included in most recent threat hunt scope
- Ask how hunt scope is derived from triggering intelligence
- Ask about CI/CD specific security tooling
- Ask for hunt scope documentation
What to require
Ask directly:
"In your most recent threat hunt triggered by supply chain threat intelligence , was your CI/CD pipeline and build environment included in the hunt scope, and if not, what is your rationale for excluding the specific environment that supply chain actors prioritise?"
Expect as evidence
- Most recent hunt scope documentation
- CI/CD inclusion confirmation or exclusion rationale
- Intelligence-to-scope alignment process
- CI/CD security tooling deployment
A vendor who confirms proactive threat hunting should be asked whether the hunt scope covered the specific environments the triggering intelligence identified as high-risk. Hunt activity is the evidence of programme operation. Scope alignment is the evidence of programme effectiveness.
How to evidence it
- Hunt scope documentation records
- Intelligence-to-scope alignment records
- CI/CD coverage confirmation
- Hunt findings summary
Key Takeaway
The intelligence said this actor targets CI/CD. The hunt did not cover CI/CD. The hunt confirmed the primary environment is clean. The actor compromised the CI/CD pipeline six weeks later. The hunt was proactive, well-resourced, and three weeks long. It investigated the environments it was scoped to investigate. The scope was not aligned to the intelligence about the actor's methodology. Threat hunting that excludes the actor's preferred environment provides assurance about environments the actor is not targeting and none about the environment they are. Derive the scope from the intelligence. Cover what the actor targets. The clean determination means something when it covers the relevant ground.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association