A security team is using an AI-powered threat hunting tool. The vendor claims 'our AI searches for unknowns - threats you don't have rules for.' A skeptical security engineer asks for a clarification of this claim. What is the technically accurate explanation?
- A.AI threat hunting is identical to signature-based detection but uses ML models as signatures
- B.AI truly detects all unknown threats with no human judgment required since it has no predefined rules to be bypassed
- C.AI-based threat hunting can detect statistical anomalies and pattern deviations from learned normal behavior without requiring pre-written rules, but it still requires human analyst judgment to determine whether an anomaly represents a genuine threat or a benign behavioral change - it surfaces unknowns for investigation, it does not identify unknowns autonomously