The Explorer is now the single home for hunts, queries, chat, and entity graphs, with a unified Activity Feed as the index (list, card, and kanban views).
Added first-run guided product tours to help new users get oriented across the app.
Redesigned the Library with richer template cards, more filter options, and a fuller detail view; hunt playbooks now share the same browsing experience.
Overhauled the query results table: per-column filters, a global search box, a more compact toolbar, and a time histogram.
Added inline query editing directly in chat, query preview cards, and the hunt canvas.
Added support for ES|QL, AQL (QRadar), and MySQL as native query languages, and separated real ES|QL execution from the older Lucene-style query option.
Added a "Scout access" toggle so connection owners can control whether Scout can use a given connection.
Added a proactive "test connection" check and smarter, auto-populated configuration fields when setting up connections; connections that don't require authentication are now supported.
Endpoint Control queries can now target endpoints by tag, operating system, or hostname — individually or combined — with per-endpoint tag management from the fleet view, plus a per-host status breakdown for running queries.
Added insight-driven hunting: incoming threat intelligence can automatically trigger investigations, and public threat-intel entities (CVEs, ATT&CK techniques, and more) are now unified with your own data in the security graph.
Reworked hunt creation into an instant "new file"-style flow: hunts open immediately as an editable draft, can be discarded if unused, and can be imported or exported as YAML.
The hunt canvas now supports full node editing — create, edit, run, and delete — from a detail side panel, and dragging a connector onto empty canvas creates a new, already-attached node.
Hunts can now be linked to structured reference entities (ATT&CK techniques/tactics, CVEs, threat actors, malware), separate from entities observed in results.
Explorer tabs now persist across page reloads, and recently closed tabs can be reopened.
Added a page-size control to Activity Feed results, and the Queries tab now shows one row per query with expandable run history instead of one row per run.
Added bulk-discard of draft hunts directly from the Activity Feed.
Query result rows are easier to read: internal system fields are hidden, nested data is flattened, and source-provided tags are now visually distinguished from your own tags.
Query notifications now include the query's name.
Connection error messages are clearer and safer, without exposing internal technical details.
Detail panels for hunts, queries, runs, and graph entities now share a consistent layout.
Simplified the entity graph by removing underused multi-select and path-finding tools.