ICSE 2025 (series) / EnCyCriS 2025 (series) / EnCyCriS 2025 /
Cyberspace Vigilante or Security Sleuth: Understanding Who Threat Hunters Are
Threat hunters play a critical role in organizational security, yet the human factors of their work and the challenges they face are often overlooked. Through interviews with 20 threat hunters, we aimed to better understand the role by investigating their personal characteristics, workflows, tools, and challenges. Our analysis of the findings resulted in the identification of 17 key dimensions of threat hunters characteristics and work practices, which informed the creation of four personas that represent the complexity of this critical role. By humanizing threat hunters, we lay the groundwork for user-centered tools that enhance their well-being and strengthen organizational security.