Added support for writing and running native SPL, KQL, and ES-DSL queries directly against Splunk, Microsoft Sentinel, and Elasticsearch connections, with full syntax highlighting for these plus Cypher and STIX in the query editor.
Added a Re-run action for hunt workspace nodes, with an option to cascade the re-run through downstream steps, plus a Regenerate action that has Scout rewrite a query node's SQL.
You can now drag to connect two existing nodes in the hunt workspace canvas.
Redesigned the Explorer into a tabbed workspace for hunts, chats, and queries, and added support for deep-linking directly to a specific query and run.
Redesigned the query creation dialog into a guided, step-by-step wizard.
Huntbase now checks that a query's tables are compatible with your selected connections before running it, catching mismatches earlier.
Query schedules can now be set to run once at a specific time, with an optional expiration.
Added an in-app feedback button so you can send feedback from anywhere in Huntbase.
Scout can now automatically analyze your query results as soon as they finish running, suggesting follow-up questions and letting you continue chatting about the data without re-running a query.
Added an "Ask Scout" option when you type a natural-language question in the query bar, instead of it being treated as a literal query.
Scout chat now queues follow-up questions submitted while a response is still in progress, instead of dropping or overlapping them.
Added the ability to cancel a running endpoint query, with clearer indication of when a run will expire.
You can now turn free-form notes into a structured insight with Scout's help, and track its review status (needs review, approved, dismissed).
Redesigned connection creation into a guided, resumable step-by-step wizard.
Added an Entity Explorer for visually investigating and pivoting across hosts, users, and other entities in the security graph, including historical time-travel and a live feed.
Added a single unified input for asking Scout, running a query, or searching.
Added support for inviting colleagues to Huntbase and accepting organization invitations, with terms-of-service acceptance during signup.
Redesigned onboarding with a unified layout and clearer progress tracking.
Improved the query editor's first-run experience: clearer input styling, accurate run attribution, a working export button, a relabeled primary action, and a live progress indicator while a query runs.
Cleaned up the Activity Feed to show only events (queries, insights, hunts) by default, with entities available in their own view.
Fixed numerous Explorer navigation issues so breadcrumbs, tab links, chat history, and URL sharing behave consistently.
Scout query recommendation cards now run reliably with a single click and display correct syntax highlighting.
Improved template library search to match on full query content, not just titles.
Connection owners can now rotate, extend, or expire their own endpoint enrollment and removal links.
The connection detail page now shows and lets you edit connection-specific configuration fields.
Chat history now shows whether a conversation relates to a hunt or a query, with badges and smart navigation to the right place.
Added a button to expand query results to a full-tab view.
Query history now shows the human-readable name of who ran each query.
Added a warning when running a query across multiple organizations with incompatible connection types.
Query editors now suggest datasets and tables based on the selected query language.
Locked the query-language selector while a template is active, to prevent accidentally switching languages mid-edit.
Scout's reasoning steps now display above its response in chat instead of below.
Fixed queries with search terms containing quotes generating invalid SQL.
Fixed some connections not appearing in list views due to a permissions sync issue.
Fixed the query schedules tab appearing empty when navigating from certain links.
Fixed the endpoint fleet page layout, an error loading agents, and unreadable install/remove commands.
Fixed several reliability issues in running and correlating queries across connections.
Fixed task and hypothesis nodes appearing without names on the hunt canvas.
Fixed Scout-triggered queries occasionally failing silently without running.
Fixed missing connections between queries, runs, and results in the security graph for some executions.
Fixed the "Save as Template" action so it works consistently everywhere a query can be created or edited.
Fixed running a saved template sometimes opening Scout chat instead of executing directly, and corrected labels distinguishing Scout-suggested, library, and custom queries.
Fixed queries with an explicit query language (Endpoint Control, STIX, Cypher) sometimes being routed to the wrong query engine.
Fixed a bug where creating a new organization could fail to complete.
Fixed file paths and command lines in endpoint query results displaying with extra escape characters.
Fixed duplicate rows occasionally appearing in the Activity Feed.
Fixed Scout occasionally showing raw technical text instead of its clarification question in chat.
Fixed Scout being unable to find connections for certain endpoint products when running queries.
Fixed duplicate responses sometimes appearing when submitting a question from the launchpad.
Fixed Scout occasionally getting stuck in a loop while searching for matching datasets.
Fixed running or editing a saved query template sometimes showing an empty query body.
Strengthened access-control checks so organization owners consistently have full permissions on their connections.
Fixed progress indicators showing zero completed connections for non-endpoint queries.