Effective threat hunting begins with asking what vulnerabilities remain undetected, since adversaries move unpredictably across systems, accounts, applications, network segments, and cloud environments seeking new exploitation opportunities. Some malicious activity appears at the endpoint while other traces are distributed across network infrastructure, making an understanding of traffic patterns essential for identifying suspicious behavior that might otherwise escape detection.