Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Intrusion Prevention System
    Threat Hunting

    Threat Hunting

    Threat hunting makes additional detections available that Netskope hasn’t or won’t deploy yet for network threat blocking because the detection is likely to alert on non-malicious traffic. These detections are a source of insight into network traffic to investigate suspicious behavior, which supports threat hunting and response and investigation use cases.

    You can view the available threat hunting detections based on your enabled traffic types. Click Configure in IPS to modify this setting.

    The Traffic Type enabled for Threat Hunting.

    Detection Configuration

    In the Detection Configuration tab, you can manually enable or disable threat hunting detections in alert or block mode on a case by case basis. If you enable threat hunting mode, some high-fidelity detections might be enabled by default, and lower-fidelity detections might be disabled by default.

    To enable or disable threat hunting detections:

    1. Go to Settings > Threat Protection > Threat Hunting.

    2. Under Detection Configuration, search for a threat hunting detection by its Detection Name or Detection ID.

    3. Click for the threat hunting detection you want to overwrite the default behavior for.

      Threat Hunting signature detection
    4. In the Edit Detection Details window:

      • Detection: The threat hunting detection you are modifying the default behavior for. You can’t modify this field.

      • Detection ID: The ID of the threat hunting detection. You can’t modify this field.

      • Status: Choose to enable or disable the threat hunting detection.

      • Action: Choose one of the following actions.

        • Alert: Netskope allows the detected traffic and generates an alert in Skope IT.

        • Block: Netskope blocks the detected traffic.

      The New Edit Detection Details window for Threat Hunting
    5. Click Save.

    You can click Show all overwritten detections to only display the detections you’ve edited.

    The Show all overwritten detections toggle.

    Module Detection

    In the Module Detection tab, you can enable or disable detection modules, which provide detection based on behavioral techniques including machine learning and advanced analytics that detect network anomalies.

    • Beacon Detection: Enable to identify evasive Command and Control (C2) beaconing, which traditional defenses often miss, by analyzing network traffic for anomalies indicative of beaconing and focusing on behavior rather than static detections for early compromise detection.

      The default action is Alert. You can’t modify this setting.

    • HTML Smuggling Detection: Enable to prevent HTML smuggling attacks and detect embedded malicious payloads inside HTML/JS files.

      The default action is Alert. You can’t modify this setting.

    Viewing Threat Hunting Alerts

    You can view threat hunting detections on the Skope IT Alerts page (Skope IT > Alerts). To view them, select Threat Hunting for the Alert Type filter.

    The Threat Hunting filter on the Skope IT Alerts page.
    In this Topic
    • Threat Hunting