Morpheus AI · Planned module · Targeted for the end of November 2026
Morpheus Threat Hunting
Everyone else turns your sentence into a query. Morpheus reconstructs what the attacker actually did.
Point Morpheus at a hypothesis and it hands back the path: one sequence across the hosts, accounts and regions it touched, ending where the attacker ended, not fourteen rows that may or may not be connected.
A query asks “Is it here?” A path asks “How far did it get?”
A hunt in Morpheus investigates every match, pivots on what it finds, and hands back the connected sequence. If nothing connects, it says so, and it records that it looked.
An alert shows one step. An attack is a sequence.
Triage is time-bound. You answer the alert in front of you and move on: a suspicious binary on one host, verdict, next. Hunting has nobody waiting. The investigation keeps going as long as the trail does: the same binary on three hosts, the same address, an account reused, a second region. That is why the deepest investigation Morpheus can run belongs in hunting, not in the alert queue.
Seven things a hunt can do in Morpheus
Hunt in plain language
Describe the technique, behaviour or ATT&CK tactic you are looking for. Morpheus builds the hunt, runs it across the connected sources and returns the path or the clean result. No query language, no pipeline.
Hunt from threat intelligence
A new advisory becomes a hunt. Indicators and techniques from your intelligence sources are checked across your environment as they arrive, not when someone has time.
Hunt on a schedule
The hypotheses that matter to you run continuously. Each run is recorded whether it finds something or comes back clean.
Report what came back clean
Ask: “Show me every technique you hunted last quarter, against which sources, and what came back clean.” A coverage dashboard tells you which rules are switched on. It does not tell you whether anybody looked. Morpheus keeps that record.
Check its own triage for mistakes
When a hunt finds an intruder that an alert should have caught, Morpheus works out why: nothing was watching for it, a tool went quiet, or its own AI closed the alert. Each reason gets a different fix, and none of them takes effect until one of your people approves it.
Test a new rule on your past data first
Before a rule is switched on, run it against the last three months. Would it have fired twice, or four hundred times? Would it have caught the thing you missed, or buried your team? Approving a change without that answer is a guess.
Build the view you asked for
Say what you need to see, in a sentence. Morpheus builds it from live hunting data, then shares it, schedules it and keeps every version. “Attack paths by business unit, worst first.” “Where did our own tools stay quiet last quarter?” “One page for the board, every month.” Every view states what data it relies on, so when something upstream changes you are told which number went stale. An ATT&CK matrix is the view most people ask for first. It should not be the only one you are allowed.
Morpheus found an intruder moving across three machines. Then it asked why nobody caught it.
Three reasons, three different fixes, and nothing changes until one of your people approves it.
Licensed the way Morpheus is licensed
Morpheus Threat Hunting is a module on your Morpheus tier and is licensed alongside it. Ninety days of hot hunting data are included, with 180 days as an option. Contact us for a quotation.
Register for early access
Existing Morpheus customers can register for early access.
Nothing changes until one of your people approves it
A hunt can propose a new continuous hunt, a coverage fix, a corrected verdict or a new rule. It cannot enact any of them. Every proposal shows its evidence, its expected effect and, for rules, what it would have done on your past data. Approval is yours.
faqs
Questions about Morpheus Threat Hunting
What is attack path hunting?
Attack path hunting is threat hunting that returns the reconstructed sequence of what an attacker did across hosts, accounts and sources, rather than a list of events that matched a query. In Morpheus, a hunt investigates every match, pivots on what it finds, and hands back the connected path or a recorded clean result.
How is this different from hunting in my SIEM?
A SIEM hunt turns a hypothesis into a query and returns the rows that matched. Deciding whether the rows are connected, and how far the activity went, is still manual. Morpheus Threat Hunting does that investigation itself and returns the path.
Is it a new hunting engine?
No. Morpheus pointed its existing investigation engine at hunting, as every agentic SOC vendor did. The difference is what that engine was built to do: reconstruct an attack, not check one alert. Pointed at a hypothesis, it returns a path rather than rows.
Is attack path hunting the same as attack path management?
No. Attack path management maps paths an attacker could take from your misconfigurations and exposures. Attack path hunting reconstructs the path an attacker did take from your telemetry. They answer different questions and are usually bought by different teams.
What is a hunt-run?
One execution of one hunt hypothesis across the connected sources, returning a verdict: path found, or came back clean. Scheduled runs, threat-intelligence-triggered runs, analyst on-demand runs and Morpheus’s own triage checks all count the same way. Viewing results, building views and running reports do not consume hunt-runs.
Does it act on its own?
No. A hunt can propose a fix, a new rule, a new continuous hunt or a corrected verdict. None of them takes effect until a person approves it.
What does it cost?
Morpheus Threat Hunting is licensed alongside your Morpheus tier. Contact us for a quotation.
When is it available?
Morpheus Threat Hunting is a planned module targeted for the end of November 2026. Existing Morpheus customers can register for early access.