Threat Hunting Coverage Calculator
Score a hunting programme on hypothesis execution, technique and data-source coverage, and conversion of findings into detections.
Inputs
Hunt Programme Score
55.4%
Hypothesis Execution Rate
62.5%
Technique Coverage Hunted
25.0%
Hunt Data Coverage
75.0%
Findings Converted to Detections
66.7%
Hunting Hours per Finding
20.0hours
Hunt Maturity
Level 2 — hunts happen but coverage and follow-through are patchy
Step by step
Values used
Hunt hypotheses planned per quarter = 24 hypotheses; Hypotheses actually executed = 15 hypotheses; ATT&CK techniques hunted in the last year = 40 techniques; Techniques in scope = 160 techniques; Data sources queryable for hunting = 18 sources; Data sources the hunt plan requires = 24 sources; Findings produced = 9 findings; Findings converted into new detections = 6 detections; Hunting hours per month = 60 hours/month
Threat Hunting Coverage
Hunt score = 0.2 × execution rate + 0.3 × technique coverage + 0.25 × data coverage + 0.25 × detection conversion rate.
Hunt efficiency
Hunting hours per finding = quarterly hunt hours ÷ findings, a blunt efficiency measure.
Hunt Programme Score
= 55.4
Hypothesis Execution Rate
= 62.5
Technique Coverage Hunted
= 25.0
Hunt Data Coverage
= 75.0
Findings Converted to Detections
= 66.7
Hunting Hours per Finding
= 20.0 hours
How it works
Conversion carries a quarter of the weight because a hunt that finds something and does not leave behind a detection has to be repeated forever. Technique coverage carries the most weight, since it is what determines whether hunting is systematically reducing blind spots or repeatedly revisiting the same comfortable ground. Hunting is expensive senior-analyst time, and without conversion and coverage metrics it drifts into unmeasurable activity that cannot be defended in a budget review.
Formulas
Threat Hunting Coverage
Hunt score = 0.2 × execution rate + 0.3 × technique coverage + 0.25 × data coverage + 0.25 × detection conversion rate.
- execution rate
- Planned hypotheses actually completed
- technique coverage
- In-scope ATT&CK techniques hunted
- data coverage
- Sources queryable versus required
- conversion rate
- Findings turned into permanent detections
Hunt efficiency
Hunting hours per finding = quarterly hunt hours ÷ findings, a blunt efficiency measure.
- quarterly hunt hours
- Monthly hours × 3, matched to the quarterly hypothesis count
Frequently Asked Questions
How is Threat Hunting Coverage calculated?
Hunt score = 0.2 × execution rate + 0.3 × technique coverage + 0.25 × data coverage + 0.25 × detection conversion rate. Conversion carries a quarter of the weight because a hunt that finds something and does not leave behind a detection has to be repeated forever. Technique coverage carries the most weight, since it is what determines whether hunting is systematically reducing blind spots or repeatedly revisiting the same comfortable ground.
Why does Threat Hunting Coverage matter?
Hunting is expensive senior-analyst time, and without conversion and coverage metrics it drifts into unmeasurable activity that cannot be defended in a budget review.
What values do I need to enter?
This calculator takes 9 inputs: Hunt hypotheses planned per quarter, Hypotheses actually executed, ATT&CK techniques hunted in the last year, Techniques in scope, Data sources queryable for hunting, Data sources the hunt plan requires, Findings produced, Findings converted into new detections, Hunting hours per month. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
Is a hunt that finds nothing a failure?
No — but it must still produce output: a documented hypothesis, the data it was tested against, and either a new detection or a recorded gap in telemetry. A negative result with evidence is coverage; a negative result with no artefact is unrecorded time.
How many hypotheses per quarter is reasonable?
For one full-time hunter, roughly 15–25 well-scoped hypotheses a quarter. Fewer usually means the scope is too broad; many more usually means they are queries rather than hypotheses.