CASE STUDY – TRANSPORTATION
How agentic AI delivered continuous threat hunting for a transport giant
DOWNLOAD THE PDFAbout the client
The client is a large transportation and logistics company operating a complex, digitally integrated supply chain. Serving enterprise customers across multiple sectors, the organization’s operations depend on deep connectivity between its own systems and those of its partners and clients. The client has a Microsoft Security stack with Microsoft Teams configured for external communications.
The client’s challenge
The client faced growing pressure to demonstrate that its security posture could keep pace with an increasingly active threat landscape.
Key challenges included:
Supply chain exposure amplifying the stakes of any breach: A compromise could cascade to customers and partners, creating both operational disruption and serious reputational damage.
Reactive threat detection leaving dangerous gaps in coverage: The team had limited ability to proactively assess the impact of emerging attack campaigns, those that hadn’t yet triggered detections.
Inability to provide timely assurance to leadership: Without a systematic way to search for indicators of new campaigns, the security team often needed days to assess impact, which left leadership without the assurance they needed.
Scaling threat hunting with limited senior expertise: The volume of hypothesis-driven hunts the team could realistically conduct was limited by available expertise. 3-5 threat hunters were needed, which was prohibitively expensive.
Benefits
- 10–15x increase in threat hunting capacity: AI-driven hypothesis generation and query adaptation delivers 150–200 hunts per month, with no equivalent increase in cost or headcount.
- Same-day assurance on emerging campaigns: When a new attack campaign is identified, the client can confirm compromise immediately, giving the CISO validated, evidence-based answers for the board.
- 2–3 new campaigns validated every week: The system continuously monitors the threat landscape and verifies emerging campaigns against the client’s full digital footprint.
- 20% increase in active detection coverage: Relevant completed hunts automatically convert into detection rules, increasing the organization’s continuous monitoring coverage.
Our solution
CyberProof implemented a continuous threat hunting capability powered by a coordinated system of four specialized AI agents.
Agent 1: Threat intelligence aggregation: Continuously collects threat intelligence from open-source and commercial feeds, structuring it into campaign profiles with the threat actor, targets, methods, and infrastructure. Matches each campaign against the client’s industry, geography, and tech stack, so only relevant campaigns move downstream, keeping signal-to-noise high.
Agent 2: Hypothesis generation: Turns each validated campaign into 30–40 structured hunting hypotheses, covering the techniques, entry points, and behavioral indicators tied to that actor. Work that would take a senior hunter days is done in minutes.
Agent 3: Environment-aware query adaptation: Converts hypotheses into precise SIEM queries tailored to the client’s actual data sources, naming conventions, and customizations. This was traditionally a dedicated hunter’s job. Solution scales without adding headcount.
Agent 4: Detection coverage: For campaigns likely to persist, converts the hunting query into a standing detection rule and folds it into continuous monitoring. Closes the loop: intelligence leads to a hunt, and every hunt leads to permanent coverage.
Throughout this process, human oversight remains central. But rather than spending their time constructing queries and processing results, senior analysts focus on interpretation and judgment, crucial work that requires their expertise. The whole agentic hunting flow is shown in the diagram below.

In early 2026, CyberProof’s agentic threat hunting capabilities demonstrated its real-world value when researchers identified a wave of targeted intrusions linked to the Iranian APT group MuddyWater (also tracked as Seedworm), exploiting Microsoft Teams to impersonate IT helpdesk staff and socially engineer employees into executing a custom backdoor infostealer known as DinDoor.
CyberProof’s agents identified the campaign signatures the same day, automatically generating hunting hypotheses and environment-specific queries that were run across the client’s full digital footprint before the threat had triggered any alerts. An attempted intrusion was identified and contained at the staging phase, well before the backdoor could establish persistence. Detection rules built from the hunt were immediately deployed as standing coverage.
Results
The result is a step change in threat hunting capacity and speed: 10–15x more hunts per month (150–200 total) at no added headcount cost, with 2–3 new campaigns validated every week as the system continuously checks the threat landscape against the client’s full digital footprint. When a new campaign emerges, the client gets same-day, evidence-based confirmation of compromise, which gives the CISO a validated answer for the board, not a best guess. And because completed hunts automatically convert into standing detection rules, active monitoring coverage grows by 20%, compounding the benefit of every hunt performed.
Speak with an expert
Looking to implement agentic AI to improve threat hunting capacity in your organization?





