Home / Case Studies / Telecom Operator
Telecommunications

Hunting a quiet intruder in the network core

A hypothesis-driven hunt across the operator's telemetry uncovered dormant persistence that automated monitoring had stepped over for months.

1
dormant intrusion confirmed and scoped
14
new detections operationalized
100%
of affected hosts identified before spread

The challenge

The operator's monitoring was alert-driven and tuned to known signatures. Leadership suspected, but could not confirm, that a sophisticated adversary could be operating quietly inside an environment of this scale and complexity.

Our approach

  • Formed hunting hypotheses from adversary tradecraft relevant to telecom infrastructure
  • Hunted across endpoint, identity, and management-plane telemetry for behavioral signals
  • Confirmed and fully scoped dormant persistence on management-plane hosts
  • Converted the findings into durable detections and handed off to containment

“Our tooling had been clean for months. The hunt found what it was never built to catch, and now those detections run automatically.”

— Head of Cyber Defense, Telecom Operator
Get ahead of zero

Ready to see yourself the way an adversary would?

Book a scoped assessment - we will map what is reachable, prove what is exploitable, and give you a ranked path to closing it before someone finds it first.

Book a free scoping call