📄️ Activity Feed
The Activity Feed is the running record of everything your team and Scout have done and found: hunts, insights, entities, query runs and reports, in one place. Open it from Activity Feed in the sidebar. Use it to see what happened in a time window, decide what needs you, and open any item without leaving the page.
📄️ Entities
Entities are the things your data keeps talking about: hosts, users, IP addresses, domains, files and processes discovered in query results, plus vulnerabilities, ATT&CK techniques and other public threat-intelligence objects Huntbase already knows about. Every entity has a detail panel and a relationship graph, and most can be turned into a hunt in one click.
📄️ Insights
An insight is a finding: a detection from a connected product, a threat-intelligence report, a watcher firing, or something an analyst or Scout recorded by hand. Insights are browsed on the Insights tab of the Activity Feed, where you can triage them, see the evidence and entities behind them, and start a hunt from any one of them.
📄️ Pulse
Pulse is the outcomes dashboard: the ROI of your threat-hunting programme — outcomes, value and maturity — rather than a count of what ran. Where the Activity Feed is your desk today, Pulse is the programme over months. Open it from Pulse in the sidebar.