Half of security professionals say poor or insufficient data is the biggest obstacle to effective threat hunting, according to the SANS 2026 Threat Hunting Survey. Gaps in cloud logging and identity telemetry are the most common complaints, and they matter most against attackers who blend in with normal activity. Without a reliable baseline of what ordinary behavior looks like, hunts generate noise while intrusions go unnoticed.

Respondents report that attackers increasingly use legitimate tools and administrator-like behavior, making signature-based hunts less useful. Cloud infrastructure is the hardest environment to hunt in, named by a third of respondents. Yet formal hunting methodology is now used by only 37% of programs, with ad hoc hunting slightly more common, likely due to staffing constraints.

Fewer teams are measuring results: 40% formally evaluate hunts, down from 64% in 2024, and only 11% say hunting improved security by 50% or more, versus 47% in 2022. The survey's author suggests teams that stop measuring may stop noticing results. Planned AI adoption also fell, from 48% to 33%, though the survey cannot say whether that reflects implementation or disillusionment.