Skip to main content

Changelog — June 22 – July 5, 2026

New Features

  • Scout can now work directly inside the hunt workspace — drafting hypotheses, creating and running hunt sessions, and streaming its analysis live as it works.
  • Added Explore, a free-text search across entities and saved queries, with rich detail previews and pivots to related data.
  • The query library and query bar now support natural-language search, with Scout stepping in to help find or build the right query when nothing matches.
  • Added Watchers — admin-defined graph patterns that can automatically start a hunt, raise a finding, or flag data when a match occurs.
  • Scout can now search and browse the web to enrich its analysis, controllable at the organization or user level.
  • Query templates can now specify which operating systems they support, so endpoint queries only run on compatible devices.
  • Added the ability to view and create schedules for query templates directly from the library.
  • New per-connection sync settings let you enable or disable scheduled queries for a connection, with upfront visibility into what will run.
  • Introduced an invite-only early access mode, showing a "coming soon" plan view for teams not yet onboarded.

Improvements

  • Scout chat now shows live status of suggested queries and prompts follow-up analysis when a query finishes or fails.
  • Added quick "New Search" and "New Chat" shortcuts to the feed creation menu.
  • Entity and node detail panels are more organized, showing triage info, related context, and provenance, with long lists (like threat intel) now capped with a "show more" option.
  • Rerunning a query now reruns it in place and shows full run history instead of creating a duplicate query.
  • Added the ability to edit and retry failed queries directly from Scout chat.
  • Public threat-intelligence data (CVEs, CPEs, IOCs, and more) now refreshes automatically and covers more sources.
  • Improved the Azure Log Analytics connector to match capabilities already available for Elasticsearch connections.
  • Emails from Huntbase — notifications, invites, and account emails — now use consistent Huntbase branding.

Bug Fixes

  • Fixed an issue where team invite links could fail for new members without an existing account.
  • Fixed scheduled query results not always appearing in the activity feed, and a related crash affecting endpoint query runs.
  • Fixed endpoint query runs that could get stuck showing as "running" indefinitely.
  • Fixed saved query results occasionally getting stuck on a loading screen when revisited.
  • Fixed Scout sometimes giving inaccurate answers about CVEs or techniques not yet in the graph, by requiring exact matches for known identifiers.
  • Fixed Scout asking for parameters that were already provided, and removed stray formatting artifacts from its chat responses.
  • Fixed a display issue where certain entities (e.g. CVEs) incorrectly showed as a generic "Public" type.
  • Fixed the query bar's search dropdown not reopening after running a deeper search.
  • Fixed an issue where a query's last-run time wasn't always saved correctly.
  • Fixed an error that could prevent starting a hunt session for some organizations.
  • Fixed occasional slow responses caused by database connections not being released promptly.
  • Fixed platform admins being unable to create platform-owned query templates.