Skip to main content

Changelog — June 8–21, 2026

New Features

  • The Explorer is now the single home for hunts, queries, chat, and entity graphs, with a unified Activity Feed as the index (list, card, and kanban views).
  • Added first-run guided product tours to help new users get oriented across the app.
  • Redesigned the Library with richer template cards, more filter options, and a fuller detail view; hunt playbooks now share the same browsing experience.
  • Overhauled the query results table: per-column filters, a global search box, a more compact toolbar, and a time histogram.
  • Added inline query editing directly in chat, query preview cards, and the hunt canvas.
  • Added support for ES|QL, AQL (QRadar), and MySQL as native query languages, and separated real ES|QL execution from the older Lucene-style query option.
  • Added a "Scout access" toggle so connection owners can control whether Scout can use a given connection.
  • Added a proactive "test connection" check and smarter, auto-populated configuration fields when setting up connections; connections that don't require authentication are now supported.
  • Endpoint Control queries can now target endpoints by tag, operating system, or hostname — individually or combined — with per-endpoint tag management from the fleet view, plus a per-host status breakdown for running queries.
  • Added insight-driven hunting: incoming threat intelligence can automatically trigger investigations, and public threat-intel entities (CVEs, ATT&CK techniques, and more) are now unified with your own data in the security graph.
  • Reworked hunt creation into an instant "new file"-style flow: hunts open immediately as an editable draft, can be discarded if unused, and can be imported or exported as YAML.
  • The hunt canvas now supports full node editing — create, edit, run, and delete — from a detail side panel, and dragging a connector onto empty canvas creates a new, already-attached node.
  • Hunts can now be linked to structured reference entities (ATT&CK techniques/tactics, CVEs, threat actors, malware), separate from entities observed in results.
  • Explorer tabs now persist across page reloads, and recently closed tabs can be reopened.
  • Added a page-size control to Activity Feed results, and the Queries tab now shows one row per query with expandable run history instead of one row per run.
  • Added bulk-discard of draft hunts directly from the Activity Feed.

Improvements

  • Query result rows are easier to read: internal system fields are hidden, nested data is flattened, and source-provided tags are now visually distinguished from your own tags.
  • Query notifications now include the query's name.
  • Connection error messages are clearer and safer, without exposing internal technical details.
  • Detail panels for hunts, queries, runs, and graph entities now share a consistent layout.
  • Simplified the entity graph by removing underused multi-select and path-finding tools.

Bug Fixes

  • Fixed an issue where viewing an endpoint in the security graph didn't surface the query that had observed it.
  • Fixed several cases where a query's status or an endpoint run appeared stuck "Running" or kept polling indefinitely after completion.
  • Fixed chat responses not auto-scrolling into view while streaming.
  • Fixed the Library page occasionally reloading unexpectedly during normal use.
  • Fixed an error when viewing endpoint connection targeting details.
  • Fixed endpoint enrollment secret retrieval failing in some environments.
  • Fixed admin-invited users still being prompted to choose a subscription plan.
  • Fixed several billing issues, including discount codes, free-plan signup, and plan updates.
  • Fixed the time-range filter appearing on query types where it had no effect.
  • Fixed a case where the app could get stuck after a new version was deployed, requiring a manual refresh.
  • Fixed duplicate hunts occasionally being created when a request was slow to respond.
  • Fixed the new-hunt tab losing focus during creation.
  • Fixed entity graph navigation and display of list-valued attributes on related nodes.
  • Strengthened access-control checks to prevent cross-organization data access and to keep platform administrators scoped to their intended resources.