Defender stories · 7 min read

From help desk to threat hunter

Most threat hunters did not start there. They started somewhere quieter, answering tickets, and they kept moving toward the noise.

The Verizon Data Breach Investigations Report has tracked thousands of confirmed breaches a year for well over a decade, and one finding holds steady across editions: a large share of incidents involve the human element, whether through error, misuse, or social engineering. Read that the right way and it stops being a warning. It becomes a job description. Someone has to sit between the people who make ordinary mistakes and the attackers who wait for them. For a great many defenders, the first chair they ever filled was the help desk.

The help desk has a reputation as the bottom rung. The defenders who came up through it tend to disagree. It is the one seat in the building where you see every system, every user, and every odd thing that happens before anyone has decided whether it matters. That is also, more or less, the definition of threat hunting.

Why the help desk is a hunting ground

A first-line analyst spends the day reading the organisation from the inside out. A laptop that will not connect. A finance manager locked out at month end. A printer behaving strangely on the third floor. Most of it is exactly what it looks like. A small fraction is not.

The person who learns to tell the difference is already doing the core work of a hunter. They build a mental model of what normal looks like, and they notice when reality drifts from it. The ENISA Threat Landscape reports describe a defensive field where speed of detection matters more than almost anything else. The help desk is where that instinct first forms, long before anyone hands you a detection platform.

The first move: from fixing to watching

The jump from support into security usually starts as a sideways step into a security operations centre, often at tier one. The work changes shape. Instead of restoring service, you triage alerts. Instead of closing a ticket and moving on, you ask whether the alert is the whole story or the first line of one.

Defenders who make this move well tend to do three things early. They learn one query language properly, so they can ask the logs a real question rather than scrolling. They read every incident write-up their team produces, including the dull ones. They volunteer for the night and weekend shifts that nobody wants, because that is when the quiet alerts arrive and the room is empty enough to actually investigate them.

Tier two: owning the whole investigation

Tier two is where a defender stops handing the hard cases up and starts keeping them. The work is no longer triage. It is ownership of an incident from the first odd signal to the written conclusion, and it carries the responsibility of deciding what is real.

A tier-two analyst spends as much time improving detection as running it. They tune the rules that generated too much noise. They write new ones for the gap an investigation exposed. This is the rehearsal for hunting, because a defender who can author a detection already understands attacker behaviour well enough to predict it. The step into hunting then feels less like a promotion and more like the natural next question.

What threat hunting actually demands

Threat hunting is the point where a defender stops waiting for the alarm. A hunter forms a hypothesis, that an attacker who got in would behave a certain way, and then goes looking for the evidence whether or not anything has flagged. It is investigative work, closer to a detective reading a scene than an operator clearing a queue.

That demands a specific blend. You need to know how attackers move, which is why frameworks that map adversary behaviour have become standard reference points across the field. You need to know your own estate well enough to spot the one process that has no business running. And you need the patience to chase something that turns out to be nothing, four times out of five, because the fifth time is the one that matters. The UK National Cyber Security Centre has long made the same point in its guidance: good defence rests on knowing your environment in detail, not on any single tool.

The certifications question, answered honestly

Newcomers ask which certificate unlocks the career. The honest answer is that none of them do, and several of them help. A foundational certification signals that you understand the vocabulary. A hands-on, practical certification signals that you can do the work under time pressure, which hiring managers weight far more heavily.

The trap is treating certificates as a substitute for evidence. A defender who can walk an interviewer through a real investigation, the alert, the pivot, the dead ends, the finding, will beat a wall of acronyms every time. Recognition follows the same logic. The Cyber Security Awards never charge to enter and never sell a place on a list, because the only thing worth recognising is the work itself, read and judged on its merits.

A Tuesday night, and the shift that changes things

Picture an archetype. A tier-one analyst, eighteen months past the help desk, working a quiet Tuesday night shift. An alert fires that the daytime team would have closed on sight: a service account logging in from a host it has never touched. The textbook says low priority. The analyst, who spent a year on the help desk learning what that account is actually for, knows it has no reason to be there at all.

They pull the logs. They follow the account across three machines. By the time the morning team arrives, they have a timeline, a contained host, and a written account of how an intruder moved. Nobody told them to look. That instinct, the refusal to accept the easy classification, is the whole job. It is also the kind of work a merit-based award exists to find, because it never comes with a press release attached.

What the path asks of you, and what it gives back

The route from help desk to threat hunter rewards curiosity over credentials and evidence over noise. It asks for unglamorous years, careful notes, and a willingness to be wrong in public when an investigation goes nowhere. In return it gives a defender something rare: the ability to look at a system nobody else finds interesting and see the one thing that does not belong.

That progression is also what the recognition categories are built to honour, from the analyst taking their first steps to the leader who shaped a team. If you are standing at the help desk now, reading every alert and wondering whether any of this leads anywhere, here is the question worth carrying into your next shift: when the easy classification is sitting right there, will you take it, or will you go and look?

FAQ

Help desk to threat hunter

Do I need a degree to become a threat hunter?

No. A degree can help and some employers prefer one, but the field weights demonstrated ability more heavily. A documented investigation, a detection you have written, or a practical hands-on certification often carries more weight in an interview than a qualification alone.

How long does the path from help desk to threat hunting take?

For most defenders it takes between three and six years, moving through help desk, tier-one and tier-two security operations, and into hunting. The pace depends less on time served than on the evidence you gather: the investigations you can show and the detections you have built.

What is the difference between a SOC analyst and a threat hunter?

A SOC analyst responds to alerts the tooling raises. A threat hunter starts from a hypothesis about how an attacker might behave and goes looking for evidence whether or not anything has flagged. Hunting is proactive investigation rather than reactive triage.

Is help desk experience genuinely useful for security?

Yes. The help desk teaches you what normal looks like across every system and user in the organisation, which is the foundation of spotting what is abnormal. Many threat hunters credit that first-line grounding for the instinct their later work depends on.