Connections can now be temporarily disabled without deleting them, pausing data collection while keeping the configuration intact.
Hunt recommendations now indicate whether a hunt can run automatically or needs analyst judgment, along with the reasoning behind each suggestion.
You can now create a tag directly from the right-click menu while tagging results, instead of switching to a separate tag manager.
Added 24 new pre-built hunts covering credential-access and lateral-movement techniques, mapped to MITRE ATT&CK.
Notifications now persist in a bell drawer with full context and follow-up actions, instead of disappearing after a few seconds.
Findings reports now support structured columns (entity, IOC, technique, recommended action, owner, status) and can be exported to CSV for handoff to incident response.
The hunt workspace now shows when Scout revises a hypothesis or proposes an alternative investigative path, along with supporting evidence.
The Library has been split into separate Templates and Playbooks sections, with structured tag filtering, a framework filter, and a list/card view toggle.
The entity feed and security graph now show accurate counts per entity type, and public entities (CVEs, MITRE techniques, CWEs, IOCs) are indexed more reliably.
Running queries can now be cancelled in place, from both the query workspace and Scout chat.
The insight panel now shows related hunts that were triggered from that insight.
Hunts in the activity feed now display a severity level.
Query steps in the hunt workspace now show full query details (content, source, connections, parameters) in the side panel, and clearly flag cases where Scout couldn't generate a query due to missing data.
AI-generated summaries now appear on insights.
Added a Kanban board view for hunts with drag-and-drop status changes, alongside the existing list view.