The Evasive Adversary and the Network Layer: What the 2026 Threat Hunting Report Means for Network Visibility

The dominant story in threat hunting right now is evasion. The CrowdStrike 2026 Threat Hunting Report, drawing on frontline hunting observations from July 2025 through June 2026, describes adversaries who no longer force their way through the front door. Instead they undermine trust: valid credentials, cloud authentication flows, SaaS applications, edge devices, and unmanaged systems, the seams between fragmented security controls where defenders often lack full visibility.

The report is candid about why this works. Adversaries “increasingly exploit areas where defenders often lack full visibility,” and they chain activity “across identity, cloud, SaaS, endpoint, and perimeter infrastructure” to establish footholds, escalate, and exfiltrate “before defenders can connect the signals and respond.” The common thread is not a single clever exploit. It is the exploitation of gaps between the tools that defenders rely on.

For anyone responsible for finding these adversaries, that raises a practical question. When an intrusion is built specifically to avoid the endpoint, the identity provider, and the perimeter appliance, where does it still leave evidence? Very often, the answer is the network.

Evasion Has a Shape, and Much of It Crosses the Network

An evasive intrusion is rarely a single event. It is a sequence: gain access through a trusted path, look around, move to something valuable, and take it. The report frames this directly, noting that disrupting these attacks “requires looking past isolated events” to hunt continuously across every domain. Several stages of that sequence produce network activity even when they produce little else.

  • Reconnaissance and enumeration. Once inside, adversaries map what is reachable. The report describes actors running “network enumeration” and probing internal services to identify lateral movement paths. Enumeration is, by definition, network traffic.
  • Lateral movement. Moving from the initial foothold to the target crosses the network between systems. It may use valid credentials and look legitimate at the identity layer, but the connection itself still happens, and still shows up in flow data as a conversation that may never have occurred before.
  • Command and control. The report documents adversaries deploying C2 agents to maintain access. C2 beaconing is a network pattern: a host reaching out to an external destination on an interval. The endpoint may be clean or unmanaged, but the beacon still traverses the network.
  • Exfiltration. Ultimately data has to leave. Whether to a cloud endpoint, a webhook, or attacker-controlled infrastructure, exfiltration is an outbound flow, often to a destination the organization has never communicated with before.

None of this requires the network to be the only place you look. It requires the network to be one of the places you look, because for an adversary who has specifically evaded the other controls, it may be the place where the activity is still visible.

An intrusion built to evade the endpoint, the identity provider, and the perimeter still has to move across the network to do anything useful. Reconnaissance, lateral movement, command and control, and exfiltration all leave network evidence, even when the other controls stay quiet.

Raw Flow Is Not Enough for Hunting

Saying “look at the network” is easy. Making network telemetry useful enough for threat hunting is harder, because raw flow data is thin. A NetFlow record shows source and destination IP addresses, ports, protocol, and byte counts. That is enough to know a conversation happened. It is not enough to hunt.

A hunter working a lead from the report’s findings needs to answer questions raw flow cannot: which user was behind that source address, what application the traffic was, whether the external destination has a known bad reputation, and where in the world it sits. Answering those from raw flow means manual, after-the-fact lookups across separate systems, exactly the kind of slow reconciliation that lets an adversary act “before defenders can connect the signals.”

For flow telemetry to support hunting at the speed the report describes, the context has to be in the record when the hunter reaches it. That is what NetFlow Optimizer (NFO) provides. NFO parses the binary NetFlow, IPFIX, sFlow, and J-Flow that network devices export, which a SIEM cannot ingest raw, and enriches every record with user identity, application, cyber threat intelligence, and geographic and network origin. A flow that would have read as one IP talking to another instead reads as a named user, running a named application, reaching a destination with a known threat reputation, in a specific country.

Hunting questionWhat enriched flow answers
Who was behind this connection?User identity resolved from AD, Entra ID, VPN logs
What was the traffic?Application name, not just port and protocol
Should we worry about the destination?Threat intelligence and reputation, GeoIP, ASN
Is this normal for this host?Full conversation record for the SIEM to baseline
Where the Hunt Actually Happens

Enriched flow telemetry is evidence, not analysis. The hunting itself, the queries, the correlation across domains, the pivots from a network signal to an identity or endpoint signal, happens in the SIEM. For most organizations, that is Splunk, where threat hunters build searches, correlate network activity with identity, cloud, and endpoint data, and run down leads. The report itself stresses hunting “across every domain” and connecting signals rather than viewing them in isolation, which is precisely a job for the SIEM as the place where domains meet.

NFO’s role is to make sure the network is a full participant in that cross-domain hunt. It delivers CIM-compliant, enriched flow telemetry into Splunk so that when a hunter correlates identity and endpoint evidence, the network layer is right there in the same searchable picture, already carrying the context that makes it useful. NFO does not detect, alert, or hunt. It ensures the network evidence the hunt depends on is present and rich enough to act on.

Why This Matters Now

Two findings in the report make the timing urgent. First, speed: from January to June 2026, 88% of observed exploitation of vulnerabilities with a public proof-of-concept happened within 48 hours of that PoC’s release, and some China-nexus actors moved within 24 hours. Second, scale: the report notes AI-agent-triggered detection leads now run at 2.5 times the rate of human-triggered ones, increasing the sheer volume and velocity of signals hunters must assess.

Faster intrusions and more signal both push in the same direction: hunters have less time and more to look at, so the evidence they work from has to be immediately usable. Network telemetry that requires manual enrichment before it means anything is telemetry that arrives too late. Enriched, in the record, ready to correlate, is what keeps the network a viable hunting surface at the speed adversaries now operates.

The Bottom Line

The 2026 threat hunting picture is defined by evasion: adversaries who exploit the gaps between endpoint, identity, cloud, and perimeter controls. An intrusion built to avoid those controls still has to cross the network to reconnoiter, move, beacon, and exfiltrate, which makes the network a place the activity remains visible. But only if the flow telemetry is enriched enough to hunt on. NFO turns raw flow into user-, application-, and threat-attributed evidence and delivers it into Splunk, so the network is a full participant in the cross-domain hunt the report calls for.

Evasive adversaries count on the seams between your tools. Enriched network visibility closes one of the seams they rely on most.

This is the first in a series on the 2026 threat hunting findings and what they mean for network visibility. Future posts look at unmanaged devices the endpoint cannot see, and at hunting when exploitation moves at AI speed.

Want the network to be a full participant in your threat hunting? Start a free 60-day trial of NetFlow Optimizer or schedule a technical demo with a NetFlow Logic engineer.

Start Free Trial  |  Schedule a Demo  |  Splunk Integration  |  NFO Documentation

Scroll to Top