📄️ Endpoints overview
Endpoints is the workspace for the hosts you manage through Endpoint Control (osctrl). It brings every endpoint from every Endpoint Control connection you can see into one place: check fleet health, find a host, tag it, run a query on it, collect a file from it, decide who may do hands-on work, and review who did what.
📄️ Endpoints and endpoint details
The Endpoints tab lists every endpoint in the fleets you can see. Use it to find a host, act on several at once, or open one endpoint's page for its details, logs and hunts.
📄️ Collect files
Collect file copies one file from one or more endpoints into a storage bucket your organization owns. Use it to pull a suspicious binary, a log or a configuration file for analysis. Collected files are stored in your bucket, never kept by Huntbase.
📄️ Access and activity
Collecting files, browsing a host's file system and running console commands are hands-on operations. The Access tab decides who may do them on a fleet's endpoints, and the Activity tab records who did — including attempts that were refused.
📄️ Files and console
An endpoint's page has two live tabs. Files lets you browse the host's file system. Console lets you run read-only commands and osquery SELECTs on it. Both talk to the endpoint in real time, both are read-only, and everything you do in them is recorded under your name.