We all understand the importance that an incident response (IR) program brings to defending the enterprise, but what is beyond that? As security professionals, how do we lead the enterprise to transition from a reactive IR model to a pro-active IR model? The purpose of this talk is to share my experiences and lessons learned on building a scalable enterprise threat hunting program. We will cover the methods behind establishing an enterprise threat hunting capability that strengthens and supplements the incident response program.