A security team is using an AI-powered threat hunting tool. The vendor claims 'our AI searches for unknowns - threats you don't have rules for.' A skeptical security engineer asks for a clarification of this claim. What is the technically accurate explanation?
- A.AI truly detects all unknown threats with no human judgment required since it has no predefined rules to be bypassed, since signature engines outlearn ML on novel threats
- B.AI-based threat hunting can detect statistical anomalies and pattern deviations from learned normal behavior without requiring pre-written rules, but it still requires human analyst judgment to determine whether an anomaly represents a genuine threat or a benign behavioral change - it surfaces unknowns for investigation, it does not identify unknowns autonomously
- C.AI threat hunting is identical to signature-based detection but uses ML models as signatures