# Cyber Threat Hunting: Find Threats Beyond Your Perimeter

> Learn how intelligence-led cyber threat hunting helps organizations detect AI-powered threats, identity attacks, and emerging risks beyond the perimeter. Explore more!

**Published:** Oct 1, 2026  
**Topics:** Cybersecurity

---

> **What are identity-based cyber attacks?**
> 
> Identity-based cyber attacks target or exploit trusted identities to gain access to systems, sensitive information, or financial assets. Attackers may use stolen credentials, synthetic identities, deepfakes, voice cloning, impersonation, or deceptive communications to pose as trusted employees, executives, customers, or other individuals and manipulate their targets.

October is Cybersecurity Awareness Month. Hosted each year by the national Cybersecurity and Infrastructure Security Agency (CISA), the event seeks to raise awareness about the cyberthreats that “put our country and economy at risk.”[1]

Top-of-mind for CISA are the industrial-scale cybercrimes enabled by AI. As the agency notes in its Cybersecurity Awareness Month briefings, “New and evolving technology such as artificial intelligence is accelerating the rate at which hackers can find and take advantage of weak spots in our computer software and systems.”[2]

AI-powered crimes require AI-powered solutions. These include intelligence-led cyber-threat hunting. By incorporating worldwide events and trends into hunting hypotheses and processes, intelligence-led cyber-threat hunting can help Security Operations Centers (SOCs) better detect and protect against both imminent risk and long-term threats.

Those threats too often target an organization’s most valuable resource: its people.

## Understanding the people problem in cybersecurity

In the age of AI, the people behind an organization — its executives, employees, constituents, and/or customers — constitute their own attack surface. This is as true for private enterprises as it is for government, military, and intelligence agencies.

AI gives impostor or disgruntled employees the power to threaten organizations. Conversely, suboptimal cybersecurity processes threaten employees and other stakeholders.

## How employees and identity-based attacks threaten organizational security

Spies and other criminals pose as job applicants to gain access to an organization or its supply chain. Their real intent is espionage, theft of proprietary information, or other crimes. For example, in 2025, North Korean nationals obtained remote jobs as IT workers for United States businesses, obtaining access to corporate computing systems.[3] Use of synthetic identities — or AI-generated personas created by combining authenticated personal data with fabricated information — makes this type of infiltration easier. So do AI-powered face-swapping technologies used during video interviews.

More often, executives and employees act as unwitting conduits for AI-generated crimes. A deepfake video of a respected president declaring his intention to bomb a non-allied country’s port may generate wide popular support for the plan. The problem? The deepfake was concocted by insurgents in the non-allied country. A scammer may email solicitations to the clients of a respected wealth management firm, using firm branding and photographs of trusted advisors. In these solicitations, the fraudster encourages clients to remit money into an account or other vehicle the fake “advisor” controls or otherwise benefits from. Conversely, that same advisor may be victimized by a scam “client” who uses voice-cloning technologies to give the advisor specific financial instructions.

Perhaps of most concern to governments and businesses, though, are [identity-based attacks](https://www.babelstreet.com/solutions/identity-risk-intelligence) that target employees to gain the credentials that provide access to governmental or corporate systems and data.

Business email compromise (BECs) is one such attack. In BECs, criminals send employees emails, IMs, and other communications, doctored to look as if they come from a trusted source: often, a superior in the organization. Their goal? To coerce employees into providing sensitive information or system access. These attacks may be committed by everyone from workaday scammers to state-sponsored cyber-attackers.

Spear fishing attacks are a type of BEC. Spear fishers study a subject’s social media posts and profiles to glean information. Using this information in communications increases the criminal’s credibility when approaching a mark. Consider this. An Army researcher and his superior are pictured attending a defense-related exposition in Washington, D.C. Someone takes a photograph of the pair, which the researcher posts on a professional networking site. A spy seeking access to military systems can contact the researcher posing as the supervisor, bolstering the researcher’s trust with a line like, “As I think I mentioned to you at the expo …”

## How cybersecurity gaps threaten employees and executives

Hacks that breach personal information can put employees at physical risk. Theft of names, addresses, phone numbers, and similar data can leave employees vulnerable to stalking, surveillance, threats of physical violence against themselves and their families, identity theft, and more.

These are real concerns for rank-and-file employees. The risk is even greater for executives and public sector leadership. As the public faces of their organizations, these VIPs are especially vulnerable to those who dislike them, their organizations, or both. AI-powered hacking can hone the danger, unveiling VIP residences, travel plans, commuting patterns, and more.

The same tactics used to threaten VIPs can harm the broader governmental or business community, especially during large events such as annual shareholder meetings, conferences, symposia, and tradeshows. AI makes it easier for terrorists and other criminals to find events, determine who is likely to attend, use building plans to plot attacks, uncover policing trends and tactics, and map escape strategies.

Traditional cybersecurity cannot detect these or any other threats percolating outside the organizational perimeter. Intelligence-lead cyber-threat hunting can.

[Video: https://fast.wistia.com/embed/medias/f7kd4qarht/]

## Where traditional cyber threat hunting and perimeter security fall short

SOCs typically hunt too narrowly for the current cyberthreat landscape. They base investigations on internal sources of data. These include reports and logs generated by security information and event management systems (SIEMs), along with data generated by other systems designed to protect networks and devices, and to detect intrusion at the organizational perimeter

No matter how sophisticated, these systems cannot be used for intelligence-led cyber-threat hunting. Why? They are unable to detect AI-powered threats percolating in the wider world. For example, they cannot find emerging activity from hackers that steal tremendous amounts of data and threaten to release it unless the victim organization meets its demands. Nor can typical SOC processes uncover espionage activities developing via the state-sponsored Iranian Advanced Persistent Threat (APT) groups coordinating on dark-web forums.

The [Babel Street Agentic Risk Intelligence Platform](https://www.babelstreet.com/platform) can help spot these threats.

## Why Babel Street for intelligence-led cyber threat hunting?

Setting a new standard for threat detection, the Babel Street Agentic Risk Intelligence platform finds and coalesces billions of pieces of publicly available information to provide governments, military organizations, the intelligence community and private enterprise with panoramic, up-to-the-second strategic threat intelligence, identity risk intelligence, and [vendor risk intelligence](https://www.babelstreet.com/solutions/vendor-risk-intelligence).

Our platform helps organizations outpace dynamic threats by incorporating worldwide events and trends into cyber-threat hunting hypotheses and processes. To do this, the platform finds and collates data from a vast collection of rights-cleared, mission-curated, multilingual signals and proprietary enrichment pipelines other providers can’t access or replicate — including hard-to-access regional data. Our data sources range from social media platforms and legacy media databases to the MITRE ATT&CK© framework, CISA malware alerts, and threat indicators — including behavioral trends, malicious IPs, and phishing schemes — bubbling on the dark web. All told, Babel Street bases its insight on more than 100 billion searchable documents, published in more than 200 languages, and translated into the user’s language of choice.

To keep ahead of emerging threats, our persistent search capabilities continuously scan this data for high-risk names, locations, date, geographies, and events — keeping search operations running regardless of whether someone is actively using them. Persistent search then records updates and changes, automatically appending this information to search terms. Social network mapping capabilities and associated visualizations help analysts understand key influencers and their roles in propagating [cybersecurity threats](https://www.babelstreet.com/solutions/strategic-threat-intelligence) worldwide — along with their connections to other people, organizations, and events.

As AI technology advances, AI-powered crime will only grow more virulent. As a global leader in mission-grade risk intelligence, Babel Street provides the type of AI-powered intelligence-led cyber-threat hunting that can help stop it.

## Frequently asked questions about cyber threat hunting

**What is intelligence-led cyber threat hunting?**
Intelligence-led cyber threat hunting uses external threat intelligence, global events, and emerging trends to guide proactive searches for cyber risks before they reach an organization’s network.

**What are the benefits of intelligence-led cyber threat hunting?**
It helps security teams detect emerging threats earlier, build stronger hunting hypotheses, uncover risks beyond perimeter tools, and prioritize the people, identities, vendors, locations, and events most relevant to their organization.

**How is AI changing the cybersecurity threat landscape?**
AI helps attackers find vulnerabilities faster, automate deceptive communications, create convincing deepfakes and synthetic identities, and scale identity-based attacks across more targets.

**How can AI-powered cyber threats target employees and executives?**
Attackers can use deepfakes, voice cloning, impersonation, and tailored messages to steal credentials, authorize fraudulent transactions, expose personal information, or gain access to sensitive systems and data.

**What are identity-based cyber attacks?**
Identity-based cyber attacks exploit stolen, fabricated, or impersonated identities to gain trusted access to systems, sensitive information, or financial assets.

**How do synthetic identities create cybersecurity risks for organizations?**
Synthetic identities combine real personal data with fabricated details to create credible personas that can bypass screening, infiltrate organizations, support fraud, and enable unauthorized access.

**What is business email compromise (BEC), and how does it target employees?**
Business email compromise is an impersonation attack in which criminals send messages that appear to come from a trusted source, often a supervisor, to trick employees into sharing sensitive information, granting access, or transferring funds.

**How can organizations identify cyber threats developing outside their network?**
Organizations can combine internal security data with intelligence from public, commercial, regional, social media, and dark web sources to identify threat actors, indicators, and activities before they reach the perimeter.

**How can persistent monitoring help detect emerging cybersecurity risks?**
Persistent monitoring continuously scans relevant names, locations, dates, geographies, and events, records changes, and alerts analysts to new information even when no one is actively running a search.

**How does dark web intelligence support cyber threat detection?**
Dark web intelligence can reveal stolen data, malicious infrastructure, phishing schemes, ransomware activity, and threat-actor coordination that may not appear in internal security systems.

**How can the Babel Street Agentic Risk Intelligence Platform improve threat detection?**
The platform unifies multilingual, mission-curated data from global sources, continuously monitors priority risks, and maps connections among people, organizations, events, and threat indicators to help teams detect and investigate emerging threats faster.

**Endnotes**

1. Cybersecurity and Infrastructure Security Agency, “Cybersecurity Awareness Month,” accessed September 2026, [https://www.cisa.gov/cybersecurity-awareness-month](https://www.cisa.gov/cybersecurity-awareness-month)

2. Ibid

3.  Federal Bureau of Investigation, “North Korean IT Workers Conducting Data Extortion,” January 2025 [https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-workers-conducting-data-extortion](https://www.fbi.gov/investigate/cyber/alerts/2025/north-korean-it-workers-conducting-data-extortion)

**Disclaimer:**

All names, companies, and incidents portrayed in this document are fictitious. No identification with actual persons (living or deceased), places, companies, and products are intended or should be inferred.