Skip to main content

Changelog — May 25 – June 7, 2026

New Features

  • Added support for writing and running native SPL, KQL, and ES-DSL queries directly against Splunk, Microsoft Sentinel, and Elasticsearch connections, with full syntax highlighting for these plus Cypher and STIX in the query editor.
  • Added a Re-run action for hunt workspace nodes, with an option to cascade the re-run through downstream steps, plus a Regenerate action that has Scout rewrite a query node's SQL.
  • You can now drag to connect two existing nodes in the hunt workspace canvas.
  • Redesigned the Explorer into a tabbed workspace for hunts, chats, and queries, and added support for deep-linking directly to a specific query and run.
  • Redesigned the query creation dialog into a guided, step-by-step wizard.
  • Huntbase now checks that a query's tables are compatible with your selected connections before running it, catching mismatches earlier.
  • Query schedules can now be set to run once at a specific time, with an optional expiration.
  • Added an in-app feedback button so you can send feedback from anywhere in Huntbase.
  • Scout can now automatically analyze your query results as soon as they finish running, suggesting follow-up questions and letting you continue chatting about the data without re-running a query.
  • Added an "Ask Scout" option when you type a natural-language question in the query bar, instead of it being treated as a literal query.
  • Scout chat now queues follow-up questions submitted while a response is still in progress, instead of dropping or overlapping them.
  • Added the ability to cancel a running endpoint query, with clearer indication of when a run will expire.
  • You can now turn free-form notes into a structured insight with Scout's help, and track its review status (needs review, approved, dismissed).
  • Redesigned connection creation into a guided, resumable step-by-step wizard.
  • Added an Entity Explorer for visually investigating and pivoting across hosts, users, and other entities in the security graph, including historical time-travel and a live feed.
  • Added a single unified input for asking Scout, running a query, or searching.
  • Added support for inviting colleagues to Huntbase and accepting organization invitations, with terms-of-service acceptance during signup.
  • Redesigned onboarding with a unified layout and clearer progress tracking.

Improvements

  • Improved the query editor's first-run experience: clearer input styling, accurate run attribution, a working export button, a relabeled primary action, and a live progress indicator while a query runs.
  • Cleaned up the Activity Feed to show only events (queries, insights, hunts) by default, with entities available in their own view.
  • Fixed numerous Explorer navigation issues so breadcrumbs, tab links, chat history, and URL sharing behave consistently.
  • Scout query recommendation cards now run reliably with a single click and display correct syntax highlighting.
  • Improved template library search to match on full query content, not just titles.
  • Connection owners can now rotate, extend, or expire their own endpoint enrollment and removal links.
  • The connection detail page now shows and lets you edit connection-specific configuration fields.
  • Chat history now shows whether a conversation relates to a hunt or a query, with badges and smart navigation to the right place.
  • Added a button to expand query results to a full-tab view.
  • Query history now shows the human-readable name of who ran each query.
  • Added a warning when running a query across multiple organizations with incompatible connection types.
  • Query editors now suggest datasets and tables based on the selected query language.
  • Locked the query-language selector while a template is active, to prevent accidentally switching languages mid-edit.
  • Scout's reasoning steps now display above its response in chat instead of below.

Bug Fixes

  • Fixed queries with search terms containing quotes generating invalid SQL.
  • Fixed some connections not appearing in list views due to a permissions sync issue.
  • Fixed the query schedules tab appearing empty when navigating from certain links.
  • Fixed the endpoint fleet page layout, an error loading agents, and unreadable install/remove commands.
  • Fixed several reliability issues in running and correlating queries across connections.
  • Fixed task and hypothesis nodes appearing without names on the hunt canvas.
  • Fixed Scout-triggered queries occasionally failing silently without running.
  • Fixed missing connections between queries, runs, and results in the security graph for some executions.
  • Fixed the "Save as Template" action so it works consistently everywhere a query can be created or edited.
  • Fixed running a saved template sometimes opening Scout chat instead of executing directly, and corrected labels distinguishing Scout-suggested, library, and custom queries.
  • Fixed queries with an explicit query language (Endpoint Control, STIX, Cypher) sometimes being routed to the wrong query engine.
  • Fixed a bug where creating a new organization could fail to complete.
  • Fixed file paths and command lines in endpoint query results displaying with extra escape characters.
  • Fixed duplicate rows occasionally appearing in the Activity Feed.
  • Fixed Scout occasionally showing raw technical text instead of its clarification question in chat.
  • Fixed Scout being unable to find connections for certain endpoint products when running queries.
  • Fixed duplicate responses sometimes appearing when submitting a question from the launchpad.
  • Fixed Scout occasionally getting stuck in a loop while searching for matching datasets.
  • Fixed running or editing a saved query template sometimes showing an empty query body.
  • Strengthened access-control checks so organization owners consistently have full permissions on their connections.
  • Fixed progress indicators showing zero completed connections for non-endpoint queries.