Datadog is introducing Bits Threat Hunting, an autonomous AI agent within Datadog Cloud SIEM designed to enable proactive, hypothesis-driven threat hunting. Unlike reactive detection rules, it continuously analyzes telemetry data—logs, network flows, identity events, and endpoint activity—to surface attacker behavior before alerts fire. The feature integrates layered threat intelligence sources including Bring Your Own Threat Intelligence (BYOTI) via reference tables, Datadog's own security research, Recorded Future for dark/open web intelligence, and Spur Intelligence for identifying anonymizing infrastructure like VPNs and proxies. The goal is to extend threat hunting capacity without requiring additional analyst headcount, and it is part of Datadog's broader autonomous SOC initiative alongside Bits Security Analyst.

5m read timeFrom datadoghq.com
Post cover image
Table of contents
Extend threat hunting coverage with Bits Threat HuntingBring layered threat intelligence into investigationsAdapt security operations to your environment
135 Impressions