Skip to main content

Changelog — May 11–24, 2026

New Features

  • Connections can now be temporarily disabled without deleting them, pausing data collection while keeping the configuration intact.
  • Hunt recommendations now indicate whether a hunt can run automatically or needs analyst judgment, along with the reasoning behind each suggestion.
  • You can now create a tag directly from the right-click menu while tagging results, instead of switching to a separate tag manager.
  • Added 24 new pre-built hunts covering credential-access and lateral-movement techniques, mapped to MITRE ATT&CK.
  • Notifications now persist in a bell drawer with full context and follow-up actions, instead of disappearing after a few seconds.
  • Findings reports now support structured columns (entity, IOC, technique, recommended action, owner, status) and can be exported to CSV for handoff to incident response.
  • The hunt workspace now shows when Scout revises a hypothesis or proposes an alternative investigative path, along with supporting evidence.
  • The Library has been split into separate Templates and Playbooks sections, with structured tag filtering, a framework filter, and a list/card view toggle.
  • The entity feed and security graph now show accurate counts per entity type, and public entities (CVEs, MITRE techniques, CWEs, IOCs) are indexed more reliably.
  • Running queries can now be cancelled in place, from both the query workspace and Scout chat.
  • The insight panel now shows related hunts that were triggered from that insight.
  • Hunts in the activity feed now display a severity level.
  • Query steps in the hunt workspace now show full query details (content, source, connections, parameters) in the side panel, and clearly flag cases where Scout couldn't generate a query due to missing data.
  • AI-generated summaries now appear on insights.
  • Added a Kanban board view for hunts with drag-and-drop status changes, alongside the existing list view.

Improvements

  • The chat query action is now labeled "Ask Scout" for clarity, with fixes to related response handling.
  • Hunts started automatically now open immediately instead of waiting on background processing.
  • Improved reliability of endpoint query connections.
  • Numerous polish fixes across the query workspace and results view, including clearer run-status wording and better connection-loading behavior.
  • Numerous polish fixes across the Library's browsing and detail views.
  • Removed a non-functional file-attachment button from chat to avoid confusion.

Bug Fixes

  • Fixed row tagging failing for certain data sources due to unstable row identifiers.
  • Fixed right-click tagging sometimes acting on the wrong row when a different row was already selected.
  • Fixed query results with nested data (e.g., profile fields, endpoint metadata) displaying as raw object text instead of readable values.
  • Fixed endpoint queries not reaching any endpoints when no specific fleet or host was selected.
  • Fixed a crash in the hunt timeline when an unrecognized activity type was returned.
  • Fixed confirmation dialogs appearing behind their parent dialog.
  • Fixed the Clear button in the activity feed's bulk-selection toolbar not actually clearing the selection.
  • Fixed Scout's reasoning trace not appearing when navigating directly to a hunt.
  • Fixed the Library and template detail pages becoming unscrollable, cutting off content.
  • Fixed the Summarize button re-enabling before the AI summary had actually finished generating, which could trigger duplicate requests.
  • Fixed deleted organizations and inactive connections occasionally still appearing in lists.
  • Fixed public entities (CVEs, MITRE techniques, etc.) sometimes being excluded from the feed and recommendations.
  • Fixed entity catalog record counts and version numbers displaying as blank in the admin view.
  • Fixed the Use Template action not working for templates beyond the first page of results.
  • Strengthened access-control checks around organization and connection management.