Skip to main content

What is Huntbase?

Huntbase is a threat hunting platform for security teams that want to find what their alerts miss. It brings your data sources, an AI investigation partner, structured hunts, and outcome tracking together in one workspace, so you can go from a question to a documented finding without switching tools.

Huntbase is built for threat hunters, SOC analysts, detection engineers, and the security leaders who need to see what hunting is delivering.

Explorer home tab with the Ask/Query launcher and the What now rail

The problem

Proactive hunting is hard to sustain. Analysts juggle a SIEM, an EDR console, cloud logs, and a notebook full of half-finished hypotheses. Queries live in personal folders, findings get lost in chat threads, and nobody can say afterwards how many hunts were run or what they caught.

How Huntbase helps

  • Explorer with Scout — Explorer is your home. It is a tabbed workspace where you ask Scout, the AI assistant, a question in plain language, or write a query yourself, and open the answer as a query tab, a chat, or a hunt. Scout translates natural language into queries, runs them across your connected sources, summarises what came back, and suggests what to look at next. See Explorer overview and Chatting with Scout.
  • Query workspace — Write and run queries in Auto (natural language), SQLite, osquery, Cypher, SPL, KQL, ES|QL, ES DSL, or STIX 2.1 against one or more connections, browse results, and save what works as a template. See Query workspace.
  • Hunts — Turn a question or a Scout chat into a structured hunt: a flow of steps that Scout and you work through together, with checkpoints where Scout stops for your call, and a report at the end. See Hunts.
  • Activity Feed — One place for everything the team has produced: hunts, insights, entities, and queries, with filters, side panels, and quick actions such as starting a hunt from an entity. See Activity Feed.
  • Pulse — The outcomes dashboard. See how many hunts ran, what was confirmed, how much was automated, and how your hunting practice is maturing over time. See Pulse.
  • Library — Reusable content: hunt playbooks you can launch as new hunts, and query templates you can run in Explorer or schedule. See Hunt playbooks and Query templates.
  • Connections — Integrate cloud, endpoint, network, identity, and threat intelligence products through the New connection wizard, and manage your osquery fleet with Endpoint Control. See Connections and Endpoint Control.
  • Watchers and Notifications — Watchers act on new insights and hunts for you (start a hunt, notify, digest, tag) within the autonomy level you allow; Notifications keep you informed in-app and by the channels you choose. See Watchers and Notifications.
info

Hunts are available to every organization. A few capabilities, such as telemetry ingest and Endpoint Control, are switched on per organization — where that applies, the app shows a Request access button and the relevant guide explains it.

Finding your way around

The left navigation has five main destinations. Everything else opens as a tab, a side panel, or a settings page from one of these.

Menu itemWhat it is for
ExplorerHome. Ask Scout, write queries, and work chats and hunts in tabs.
PulseOutcomes dashboard for your hunting practice.
Activity FeedBrowse and triage hunts, insights, entities, and queries.
LibraryHunt playbooks and query templates to launch, run, or schedule.
ConnectionsAdd and manage data sources, including Endpoint Control.

Above the content, the Target selector in the page header controls whose data you are looking at: one or more organizations, your Personal scope where your account has one, or All Contexts. Settings for you and for each organization live under Settings › Personal and Settings › [Organization].

Left navigation with Explorer, Pulse, Activity Feed, Library, Connections and the Target selector in the header

How a hunt flows through Huntbase

  1. Connect a data source once.
  2. Ask Scout a question in Explorer, or write the query yourself.
  3. Investigate in a query tab: pivot through results, entities, and insights.
  4. Hunt when the question deserves structure: Scout plans the steps, runs the safe ones, and pauses at checkpoints for your decision.
  5. Report the outcome and let Pulse track it alongside every other hunt.

A hunt overview tab showing the flow graph with a checkpoint awaiting approval

Two ways to work

You do not have to choose between chatting and querying. The launcher on the Explorer home tab has an Ask mode and a Query mode:

  • Ask sends your question to Scout, which opens a chat, works out the query, runs it, and summarises the results with follow-up suggestions.
  • Query gives you the query editor directly. Pick a language, pick connections, and press Enter to open the results in a query tab. If you type plain English here instead, Huntbase quietly hands it to Scout.

Both paths land in the same tabbed workspace, so you can start in one and continue in the other.

tip

New to Huntbase? Start with Ask. Scout will show you the query it wrote, and you can open it in a query tab and edit it whenever you want more control.

The Ask / Query toggle above the launcher on the Explorer home tab

What Huntbase is not

  • Not a SIEM. Huntbase does not ingest and store all your logs. It queries the products you connect where they already live, and keeps the outcomes: queries, results you keep, entities, insights, and hunt reports.
  • Not an alert queue. Insights and watchers exist to feed hunts, not to replace your triage tooling.
  • Not a black box. Every Scout action shows its steps, the query it ran, and where the results came from, so you can check the work.

Who is this for?

  • Threat hunters running hypothesis-driven investigations across many sources
  • SOC analysts who need to answer "is this bad?" fast, with the query written for them
  • Detection engineers building and sharing playbooks and templates
  • Security leaders who want visibility into hunting outcomes, not just activity

Next steps