Change-Triggered Hunts
Exploiting Network Turbulence to Pressure Adversary Persistence
By Geoffrey Crawford
| Gray Space, 2026 E-Edition
Read Time: < 15 mins
The Cyber Operations Center at Fort Gordon, GA, is home to signal and military intelligence noncommissioned officers, who watch for and respond to network attacks from adversaries as varied as nation-states, terrorists, and “hacktivists.” (Photo by U.S. Army)
This article was edited with the assistance of artificial intelligence (AI) tools. Final review and editing were conducted by authorized DoW personnel to ensure accuracy, clarity, and compliance with DoW policies and guidance.
Introduction
An Army network begins a scheduled replacement of its endpoint security tools across key systems. The network owner knows which hosts should receive the new agent, which services should stop and restart, which administrative accounts should execute the change, and what temporary telemetry degradation to expect. The Regional Cyber Center shares recent reports that the network’s mission set aligns with current adversary targeting and that the enclave has shown suspicious authentication patterns during the previous 60 days. Instead of treating the maintenance window as a routine technical event, U.S. Army Cyber Command (ARCYBER) aligns a Cyber Protection Team (CPT) to monitor the network with a defined hunting hypothesis. The team watches for hosts that fail to receive the new agent, services that reappear under unauthorized names, privileged activity from accounts outside the approved change roster, and outbound connections that resume as visibility drops. In that moment, the hunt is not abstract. It is tied to a known change, a prioritized network, and a narrow set of behaviors that may reveal whether an adversary is preserving or re-establishing access.
Every day across the Army enterprise, networks and endpoints undergo updates. Some of these changes are minor and have little impact on network architecture or operations. Others are significant events that alter network topography, endpoint configuration, security tooling, identity management, or administration. These periods of network turbulence create decision points for adversaries. A persistent actor can use the confusion of a major update to move with less risk of notice, exploit misconfigurations, or take advantage of reduced confidence in what normal should look like. At the same time, those same changes can create risk for the adversary. Persistence mechanisms may fail, privileged access may be disrupted, beaconing patterns may change, or tooling may become more visible as defenders compare intended changes against actual outcomes. This creates an opportunity for defensive cyber forces. If defensive teams deliberately hunt during significant change windows, they can pressure the adversary decision cycle, improve response time to anomalies identified during updates, and provide greater support for Department of War Information Network (DOWIN) security. A major change window gives defenders a narrower, better-framed hunting hypothesis than a generalized question of whether an adversary is somewhere in the network. This framing is consistent with NIST’s emphasis on ongoing awareness of security posture, vulnerabilities, and threats to support risk-based decisions (Dempsey et al., 2011; Dempsey et al., 2020).
The Army should therefore treat significant network and endpoint changes as deliberate counter-persistence windows. Before the change, CPTs should coordinate with network owners and Regional Cyber Centers (RCCs) to baseline the network and identify the systems, accounts, services, and expected behaviors associated with the update. During the change, defenders can compare intended versus actual states while persistent adversaries may have to validate access, repair broken persistence, or exploit the turbulence to advance their objectives. After the change, CPTs can look for signs of adversary reentry, degraded visibility, suspicious reconfiguration, and gaps in sensor coverage. Coordinated hunting by network owners, RCCs, and CPTs can convert periods of technical risk into opportunities for focused detection, assurance, and validation. That logic aligns with NIST’s security-focused configuration-management guidance, which emphasizes establishing secure baselines, controlling changes, and monitoring them over time (Johnson et al., 2019; Joint Task Force Interagency Working Group, 2020, CM-2, CM-3, and CA-7).
Significant changes for this purpose should include events such as enterprise patch cycles, Active Directory restructuring, endpoint security tool replacement, large software deployments, network re-segmentation, and major identity or authentication stack changes. These are the moments when defenders already know that unusual but authorized activity will occur, when approved administrative behavior can be scoped in advance, and when deviations from that behavior can be investigated quickly. They are also the moments when flaw remediation and configuration-change control intersect most visibly in practice, which is why NIST treats both as core security-control functions rather than purely technical-maintenance tasks (Joint Task Force Interagency Working Group, 2020, SI-2 and CM-3).
Why Steady-State Hunting Is Hard
Army networks are large, diverse, and constantly changing. New technologies, shifting missions, modernization efforts, and defensive requirements create an environment where the terrain rarely remains static for long. Adversaries adapt to this same reality. They are patient, deliberate, and often willing to invest significant time in establishing and preserving access. These realities make steady-state hunting difficult. Defensive teams often choose between broad intelligence-driven hunts, which depend heavily on the quality of available intelligence, and incident response, which usually occurs after adversaries have already created a problem. Both are necessary, but neither consistently place defensive teams on the network at the exact moment an adversary may need to act. Significant change windows can help close that gap.
Defensive cyber operations rely heavily on intelligence to gain the initiative. Intelligence allows teams to align hunt activity to a threat actor, malware family, technique, or specific set of indicators. That remains necessary, but it does not always provide temporal advantage over a patient adversary. Timing matters. When defenders are present in the network while the adversary is validating access, re-establishing persistence, or exploiting transition, they gain a better opportunity for detection than they would by hunting after the fact. Otherwise, defenders often depend on log retention, delayed artifacts, or the chance that the adversary is active during the hunt window. If an adversary notices that a CPT is conducting a hunt during normal operations, that actor may simply remain dormant until the hunt is complete. During significant network change, however, the adversary may have a stronger incentive to interact with the environment even when the CPT is present. That pressure can increase the probability of mistakes or detection. The adversary may need to determine whether an implant survived, whether credentials still function, whether remote-access pathways remain open, or whether a misconfiguration created a new opportunity. These behaviors map directly to widely observed adversary tradecraft in the MITRE ATT&CK knowledge base, including persistence through scheduled tasks, Windows services, registry run keys, and abuse of valid accounts (MITRE ATT&CK Enterprise, 2015; MITRE ATT&CK Enterprise, 2017a; MITRE ATT&CK Enterprise, 2022; MITRE ATT&CK Enterprise, 2020; MITRE ATT&CK Enterprise, 2017b).
How Intelligence Selects the Right Networks
Intelligence should do more than support the hunt after a CPT is already committed. Intelligence should determine where the Army applies change-triggered hunts in the first place. The Army does not have enough CPT capacity to hunt every major change across the DOWIN, and the probability of adversary presence is not equal across all networks. For that reason, commanders and defenders should prioritize change-triggered hunts where three factors overlap: The network carries high mission value, intelligence indicates credible adversary interest or historical access, and a significant authorized change could disrupt or expose persistence. This makes intelligence the screening mechanism that converts a broad enterprise idea into a practical operational method.
In practice, that prioritization should combine mission analysis, intelligence reporting, and network context. Intelligence organizations can identify networks associated with current adversary targeting, sensitive data, critical mission functions, and known exploited vulnerabilities; simultaneously, RCCs can provide prior anomalous authentication or beaconing and previous-hunt findings. Network owners can add context about upcoming changes, administrative complexity, dependencies, and likely visibility gaps. CPTs can then apply their limited capacity against the subset of changes that combine mission consequence with credible adversary opportunity. This approach preserves the value of intelligence-driven hunting while using significant change as a timing mechanism. Intelligence identifies where to hunt. The change event identifies when to hunt.
This approach also prevents change-triggered hunting from becoming a blanket requirement. Not every patch cycle justifies a CPT. Not every network carries the same operational value. Not every change creates equal opportunity to expose adversary behavior. Intelligence should therefore support a simple prioritization model built around network criticality, adversary targeting, historical suspicious activity, significance of the change, and the consequence of missed persistence. If those factors do not converge, the Army should preserve CPT capacity for higher-value opportunities.
What a Change-Triggered Hunt Is
Change-triggered hunts should focus on one central question: Did only the intended changes occur, or did malicious persistence survive, adapt, break, or reveal itself? That question gives this form of hunting its value. CPTs should coordinate with the network owner and RCC to baseline the devices, accounts, services, log sources, and administrative actions associated with the change. Once the baseline is established, the participating organizations must define the behaviors expected during and after the update. Based on those expectations, the CPT can identify anomalous behaviors that may indicate adversary presence and build analytics, dashboards, and hunt packages to support rapid detection. The team should focus on a relatively narrow subset of suspicious activity, including persistence mechanisms, privileged access abuse, suspicious reconfiguration, abnormal authentication patterns, unauthorized service creation, post-change reentry attempts, or unexplained degradation of visibility.
This is what separates a change-triggered hunt from a generalized enterprise hunt. In a broad hunt, analysts may have to evaluate many possible behaviors across many parts of the network with limited context on where and when an adversary is likely to act. In a change-triggered hunt, the defenders know that a major authorized event is occurring, know what should be changing, and know where the adversary may have to adapt. That does not make the hunt easy, but it does make it more refined. Rather than asking whether an adversary exists anywhere in the network, the team asks whether the authorized change created signs of adversary disruption, adaptation, or exploitation. That bounded framing reduces mission creep and improves analytic focus. MITRE ATT&CK’s detection guidance for valid account abuse emphasizes anomalous logon patterns, abnormal logon types, and inconsistent time- or context-based activity, all of which become more actionable when defenders understand the expected administrative behavior for a specific change window (MITRE ATT&CK Enterprise, 2017a).
A Practical Three-Phase Model
This concept works best when teams organize the hunt in three phases: before, during, and after. Before the change, CPTs, RCCs, and network owners should establish baseline conditions, confirm expected update behavior, identify critical log sources, validate sensor coverage, and build hunt analytics tied to the change. During the change, the defensive team should monitor for divergence from expected behavior, watch for suspicious authentication or privilege events, track visibility gaps, and compare observed system states to the approved implementation plan. After the change, the team should shift attention to signs of adversary recovery or reentry. This includes monitoring for re-established persistence, reintroduced unauthorized accounts, suspicious service recreation, abnormal outbound connections, or delayed attempts to regain access after the environment stabilizes. This phased model keeps the hunt from collapsing into a single point-in-time event and instead surrounds the full change window with deliberate defensive action.
A useful example is a scheduled replacement of enterprise-endpoint security tools across a brigade’s key systems. Network owners know which hosts should receive the new agent, which administrative accounts should be active, which services should stop and start, and what temporary degradation in telemetry is expected. The CPT can use that plan to watch for hosts that fail to receive the agent, services that are recreated under unexpected names, administrative activity from accounts outside the approved change roster, or outbound connections that resume immediately after visibility drops. In that scenario, the hunt is tied directly to a bounded change event, a known set of expected behaviors, and a realistic set of opportunities for adversary adaptation.
This model mirrors established federal-security practice more than it departs from it. NIST’s continuous monitoring guidance is built around maintaining awareness over time, while its security-focused configuration management guidance stresses inventories, baselines, approved changes, monitoring, and reassessment (Dempsey et al., 2011; Johnson et al., 2019).
Capt. Seth Hayden of the Army Cyber Protection Brigade monitors exercise progress in the white team operations area for exercise Operation Tiger Stance at the Indiana National Guard’s Muscatatuck Urban Training Center in Butlerville, IN, August 23, 2018. (Photo by Bill Roche)
Long-Term Visibility and Sensor Assurance
Change-triggered hunts also create an opportunity that extends beyond the immediate maintenance window. Because CPTs, RCCs, and network owners must already verify expected system states and telemetry during the hunt, they can use the event to confirm that sensors are properly deployed, that critical log sources remain active, and that required data is feeding into centralized platforms for future remote analysis. If a host loses endpoint visibility during a tool migration, if a subnet is not forwarding logs after re-segmentation, or if an authentication source is absent from enterprise collection after an identity change, the team can identify and work with network owners to correct those gaps while the change is still under active control.
That matters for more than local assurance. Remote hunting depends on durable visibility. A CPT cannot effectively investigate future anomalies across the DOWIN if endpoint agents are unevenly deployed, if logs are not normalized into centralized feeds, or if key systems fall out of collection after major changes. Change-triggered hunts therefore support two objectives at once: They help detect malicious adaptation in the moment, and they help preserve the sensor coverage and centralized data feeds that make future remote hunts possible. In that sense, the hunt does not only answer whether the adversary reacted to the change: It also confirms whether the Army retained the visibility required to find that adversary later if the actor remains dormant during the initial window.
Why This Helps the Defender
This concept also provides a force-management advantage. In many cases, CPTs do not receive warning before incident response becomes necessary. A change-triggered hunt deliberately places the team in position before a likely point of adversary decision. If the team identifies something anomalous, the CPT is already on the terrain, oriented to the environment, and coordinated with the network owner and RCC. That can reduce the time required to understand what happened, accelerate containment decisions, and decrease the friction that usually accompanies a no-notice incident response. It also allows the CPT to validate that visibility remains intact, and that accurate network topology and endpoint understanding are preserved for future remote hunts.
This approach also aligns with broader public-sector guidance on reducing exposure to exploited vulnerabilities and configuration weaknesses. The Cybersecurity and Infrastructure Security Agency (CISA) maintains the Known Exploited Vulnerabilities Catalog as an authoritative list of vulnerabilities that are exploited in the wild and explicitly recommends that organizations prioritize remediation of the listed items. When those remediation actions require major change, it is reasonable to treat the associated maintenance window as both a risk event and a detection opportunity rather than as a purely administrative exercise (CISA, n.d.).
Limits and Cautions
There are important limits to this concept. Not every major update will cause an adversary to reveal itself. Sophisticated actors may choose to remain dormant, accept temporary uncertainty, or rely on redundant persistence mechanisms that survive the change without generating clear indicators. Major updates also create benign anomalies, and poor change documentation can increase the burden of false positives on defenders. For that reason, change-triggered hunts should not replace intelligence-driven hunts or incident response. They should complement them. Their value lies in exploiting a narrow window when adversary adaptation may become more visible and when defenders can combine local context with regional visibility to increase the probability of detection. Due to the sheer size of the DOWIN, not all changes should or could warrant a change-triggered hunt. Intelligence remains critical for refining which opportunities to leverage in this style of hunt. Assessments of critical or high-value networks or network functions should remain a core differentiator in choosing the type of hunt to execute.
New York Army National Guard Soldiers assigned to the 173 Cyber Protection Team plan their next move during an exercise which took place at the Kingston Armory in Kingston, New York from February 23 to 26, 2026. (Photo courtesy 173 CPT)
That caution is important for analytic credibility. The claim is not that every update exposes a hidden adversary. The claim is that significant changes create conditions under which adversary persistence, service modification, startup persistence, and valid-account abuse may become easier to frame and detect if defenders are prepared in advance. MITRE ATT&CK documents these mechanisms because they are repeatedly observed in the real world; NIST documents the monitoring and configuration practices needed to notice them with discipline (MITRE ATT&CK Enterprise, 2015; MITRE ATT&CK Enterprise, 2022; MITRE ATT&CK Enterprise, 2020; MITRE ATT&CK Enterprise, 2017b; Johnson et al., 2019; Dempsey et al., 2011).
Conclusion
The Army should treat significant authorized network and endpoint changes as more than maintenance events. These are moments when terrain is genuinely contested and defenders are more likely to come into contact with an active adversary. During these periods, defenders intentionally alter the environment, administrators operate at an elevated pace, and adversaries may have to decide whether to observe, adapt, exploit, or risk losing access. That makes these windows uniquely valuable for coordinated hunting. By aligning CPTs, network owners, and RCCs before, during, and after major updates, the Army can convert routine technical risk into deliberate counter-persistence opportunity. If the Army also uses intelligence to identify the right networks and uses each hunt to validate sensor coverage and centralized data feeds, this concept gains both immediate and enduring value. In an environment where patient adversaries often choose the time and place of interaction, change-triggered hunts offer defenders a practical way to apply pressure at a moment when the adversary may have fewer options and less room to hide.
References
CISA. (n.d.). Known exploited vulnerabilities catalog. Cybersecurity and Infrastructure Security Agency CISA. https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Dempsey, K. L., Chawla, N. S., Johnson, L. A., Johnston, R., Jones, A. C., Orebaugh, A. D., Scholl, M. A., & Stine, K. M. (2011). Information Security Continuous Monitoring (ISCM) for federal information systems and organizations. National Institute of Standards and Technology. https://doi.org/10.6028/nist.sp.800-137
Dempsey, K., Pillitteri, V. Y., Baer, C., Niemeyer, R., Rudman, R., & Urban, S. (2020). Assessing information security continuous monitoring (ISCM) programs: Developing an ISCM program assessment. National Institute of Standards and Technology. https://doi.org/10.6028/nist.sp.800-137a
Johnson, A., Dempsey, K., Ross, R., Gupta, S., & Bailey, D. (2019). Guide for security-focused configuration management of information systems. National Institute of Standards and Technology. https://doi.org/10.6028/nist.sp.800-128
Joint Task Force Interagency Working Group. (2020). Security and privacy controls for information systems and organizations. National Institute of Standards and Technology. https://doi.org/10.6028/nist.sp.800-53r5
MITRE ATT&CK Enterprise. (2015). Persistence - Enterprise | MITRE ATT&CKTM. Mitre.org. https://attack.mitre.org/tactics/ta0003/
MITRE ATT&CK Enterprise. (2017a, May 31). Scheduled Task/ Job. Mitre.org. https://attack.mitre.org/techniques/t1053/
MITRE ATT&CK Enterprise. (2017b, May 31). Valid Accounts. Mitre.org. https://attack.mitre.org/techniques/t1078/
MITRE ATT&CK Enterprise. (2020, January 23). Boot or logon autostart execution: Registry run keys / Startup folder. Mitre.org. https://attack.mitre.org/techniques/t1547/001/
MITRE ATT&CK Enterprise. (2022, January 17). Create or modify system process: Windows service. Mitre.org. https://attack.mitre.org/techniques/t1543/003/
Author
Maj. Geoffrey Crawford is an instructor for Cyber Warfare Officer Basic Officer Leaders Course (CWO-BOLC) in the 401st Cyber Battalion. Prior to serving in the 401st, Maj. Crawford attended resident Command and General Staff College (CGSC) at Fort Leavenworth, Kansas. Before CGSC, he was assigned to the Cyber Protection BDE, where he held positions as a Cyber Protection Team (CPT) Team Lead, battalion S-1, and Mission Element Lead. Maj. Crawford served as a Team Lead for 503 CPT, which supported USINDOPACOM and the Team Lead for 156 CPT, an Army service team focused on Industrial Control Systems technology. He was the Mission Element 1 lead for 91 CPT, which is the only Army team that supports the DoW Information Network (DoWIN).