threat-hunting services

Zscaler Threat Hunting Service

Reduce Alert Fatigue: Zscaler Threat Hunting (ZTH) hunts for covert, sophisticated attacks to prevent potential breaches. ZTH helps organizations facing emerging threats that overwhelms their SOC team with too many alerts and leading to overlooked breaches.

Security Talent Shortage: In the current global security talent shortage, defenders are overloaded despite having access to an abundance of tools and data. ZTH helps organizations by becoming an extension of their SOC team and helping them defend against threats.

SOC Augmentation: ZTH Advanced and ZTH Advanced Dedicated offerings provide you with access to the expertise you need to tackle your most challenging threat-hunting related needs. Our ZTH analyst will work with your team to plan and guide your security team’s threat hunting activities, leveraging the experience of past engagements to reduce security risks and enhance defensive capabilities.

Zscaler Threat Hunting Tiers

Data Retention Period
Retro-Hunt Duration
SOC Augmentation
24x7x365 Coverage
Tailored Hunting
Reports & Analytics
Onsite Visits (Annually)
Policy Recommendations
SKU
Essentials
90 days
30 days
Detection Only
ZTH-ESS
Advanced
90 days
60 days
Designated Hunter
ZTH-ADV
Advanced Dedicated
90 days
90 days
Dedicated Hunter
ZTH-DED

ZTH is a professional service that runs on top of other Zscaler Software as a Service (SaaS) products, to perform human-led threat hunting to identify suspicious and potentially malicious threat patterns to better detect threats and enable response to incidents.

ZTH is priced according to the number of licenses required for the subscription of the underlying SaaS products (e.g., number of seats, workloads, etc.). For example, a customer of Zscaler Internet Access (ZIA) who wishes to purchase the ZTH service must pay a fee based on the number of ZIA licenses required to be purchased by the customer for the remainder of the then-effective ZIA subscription term.

Customers are required to purchase the ZTH service in accordance with the number of licenses required for the underlying SaaS products. For example, the number of seat licenses required for a customer of ZIA is determined by counting the unique individual users of ZIA over the previous rolling 90-day period. Therefore, a customer who purchases ZTH service for ZIA would pay the corresponding fee.

ZTH Advanced Dedicated is an add-on to the ZTH Advanced service that provides one U.S.-based Dedicated Hunter that's available 8:00AM - 5:00PM, Monday through Friday. This schedule excludes Zscaler recognized public holidays, as well as days the Dedicated Hunter is on approved leave, including but not limited to sick leave, vacation time, and other time off permitted under Zscaler company policy. Zscaler makes reasonable efforts to notify customers in advance of any such absences when possible, but cannot guarantee substitute coverage of all absences.