📄️ Explorer overview
Explorer is where you land when you open Huntbase and where most of your work happens. It has two parts: the dock on the left — a rail of views over your hunts, chats, queries, templates and Scout — and a tabbed workspace beside it, with a pinned Home tab (a launcher, suggested chats and a worklist) and one tab per chat, query, or hunt you have open. Nothing you open here is lost when you switch tabs — a running query keeps streaming and a half-typed chat message stays put.
📄️ Chatting with Scout
Scout is Huntbase's AI assistant. You talk to it in a chat tab inside Explorer: ask a question in plain language and Scout works out what to run, picks connections, runs it, and explains what came back. Along the way it posts cards you can act on — a query to confirm, a clarifying question, a hypothesis to turn into a hunt.
📄️ Query workspace
A query tab in Explorer is where you write and run queries against your connected data sources, your endpoint fleet, or the Huntbase entity graph. Every query tab has the same layout: a query bar along the top, an optional parameter strip below it, and a results pane that fills the rest of the tab.
📄️ Search telemetry
Search shows the raw events your log shippers send to Huntbase. Type a value or a field:value filter, or click values in the results to filter by them. Huntbase writes the search as a query, so you can open the exact query behind what you see, run it, save it, add it to a hunt or schedule it.
📄️ Hunts
A hunt keeps an investigation together one tab with five views — Notebook, Results, Flow, Entities and Timeline — plus a Report tab and the hunt's chats. The dock's Workspace tree lists the same folder for every hunt you can see.
📄️ Entity timeline
The entity timeline shows everything Huntbase knows about one host, user, IP address or file hash, newest first, in a single list. It answers "what happened on hr-ws-03?" or "where has this hash shown up?" without searching telemetry, the entity graph, hunts and alerts one at a time.
📄️ Tags and notes
As you work a hunt you mark what matters. A tag records a judgement, such as Suspicious, Compromised or Known Good. A note records your reasoning in your own words. Tags and notes are saved and shared with everyone who can see the same data. Huntbase reads them back when it builds the hunt's investigation timeline, the tracker spreadsheet and the hunt report.
📄️ Investigation timeline
A hunt's investigation timeline is the story of the incident as you tell it. It lists only the events you decided matter, oldest first, in UTC: when the attacker got in, what they touched, what you did about it. Each event can link back to the row, entity or endpoint it came from.
📄️ Tracker spreadsheet
The tracker spreadsheet exports a hunt as an Excel workbook for tracking an incident. It has one master timeline, then a tab for each kind of artifact: systems, malware and tools, accounts, network indicators, exfiltration, evidence, action items and notes. Every time is in UTC. Hand it to an incident responder, attach it to a ticket, or keep working in it after the hunt is closed.
📄️ Hunt reports
A hunt report is the written account of a hunt. Scout writes it from the hunt's own evidence: its steps and results, the entities it found, and your tags, notes and investigation timeline. The template you pick sets its shape. You read it in the hunt's Report tab and download it as a Word document or Markdown.