Skip to main content

Changelog — July 6–19, 2026

New Features

  • Added Watchers: admin-authored rules that continuously watch your security graph and, on a match, automatically start a hunt, raise an alert, add to a daily digest, or tag data for later use.
  • Hunts and queries are now private to their creator by default. Org admins can grant broader visibility or explicit sharing as needed.
  • Insight details now show enrichment from CVE and MITRE ATT&CK data directly in the panel, and fixed a bug where insight descriptions sometimes failed to display at all.
  • Added a general-purpose webhook for ingesting OCSF-formatted alerts, making it easier to connect external detection sources into Huntbase.
  • The hunt workspace now has a Provenance view showing what triggered a hunt (a watcher, an insight, a template, or a manual start), along with a refreshed hunt canvas.
  • Queries, runs, and hunts now show who created them — a teammate or Scout — with a creator filter in the activity feed.
  • Redesigned the Library with a persistent sidebar for browsing by content type (queries, collections, actions, hunt playbooks), plus faster loading.
  • Scout can now reference entities inline in chat as clickable chips that open the entity card, for both public threat-intel entities and your own tenant's entities.
  • Overhauled Scout's threat-hunting approach with improved plan and hypothesis quality, added tradecraft guidance, and memory that carries context across related hunts.
  • Scout now remembers your last-selected initiative (effort) level and uses it as the default for new chats.

Improvements

  • Removed a confusing, non-functional time-travel slider from the entity detail panel.
  • The home screen's Ask box now matches the full chat input, including the initiative selector.
  • Fixed several places where Scout's analysis notes, findings, and monitoring messages displayed raw markdown instead of formatted text.
  • Cleaned up naming for query languages in the library, removing a redundant, confusingly-labeled option.
  • Scout's query suggestions now use only the connections that are actually applicable to a given query.
  • Improved the performance and stability of the security graph as data volumes scale.
  • Improved overall app stability and responsiveness under heavy load.

Bug Fixes

  • Fixed a blank detail panel when viewing analytic nodes in the hunt flow.
  • Fixed query runs failing for connections that don't require credentials, such as public data sources.
  • Fixed Endpoint Control query runs sometimes showing as complete before all results had finished loading, or getting stuck/marked failed while still running.
  • Fixed several issues in the query workspace where switching between runs or queries could get stuck, flicker, or lose your place in the browser URL.
  • Fixed "Open in tab" from the hunt panel not loading a query's previous results.
  • Fixed hunts created from Scout chat sometimes not appearing in the conversation.
  • Fixed org admins and owners not always being able to see hunts, queries, and runs created by other members of their team.
  • Fixed a data-lookup mismatch that caused entity extraction to miss data for a large share of endpoint queries.
  • Strengthened tenant data isolation on export and data-read endpoints.
  • Catalog-provided watchers are now off by default, so they no longer unexpectedly re-enable after platform updates.
  • Fixed queries added to an in-progress hunt sometimes being tagged with the wrong query language.
  • Added a clear error message instead of a crash when a hunt step references a deleted query.