Added Watchers: admin-authored rules that continuously watch your security graph and, on a match, automatically start a hunt, raise an alert, add to a daily digest, or tag data for later use.
Hunts and queries are now private to their creator by default. Org admins can grant broader visibility or explicit sharing as needed.
Insight details now show enrichment from CVE and MITRE ATT&CK data directly in the panel, and fixed a bug where insight descriptions sometimes failed to display at all.
Added a general-purpose webhook for ingesting OCSF-formatted alerts, making it easier to connect external detection sources into Huntbase.
The hunt workspace now has a Provenance view showing what triggered a hunt (a watcher, an insight, a template, or a manual start), along with a refreshed hunt canvas.
Queries, runs, and hunts now show who created them — a teammate or Scout — with a creator filter in the activity feed.
Redesigned the Library with a persistent sidebar for browsing by content type (queries, collections, actions, hunt playbooks), plus faster loading.
Scout can now reference entities inline in chat as clickable chips that open the entity card, for both public threat-intel entities and your own tenant's entities.
Overhauled Scout's threat-hunting approach with improved plan and hypothesis quality, added tradecraft guidance, and memory that carries context across related hunts.
Scout now remembers your last-selected initiative (effort) level and uses it as the default for new chats.
Fixed a blank detail panel when viewing analytic nodes in the hunt flow.
Fixed query runs failing for connections that don't require credentials, such as public data sources.
Fixed Endpoint Control query runs sometimes showing as complete before all results had finished loading, or getting stuck/marked failed while still running.
Fixed several issues in the query workspace where switching between runs or queries could get stuck, flicker, or lose your place in the browser URL.
Fixed "Open in tab" from the hunt panel not loading a query's previous results.
Fixed hunts created from Scout chat sometimes not appearing in the conversation.
Fixed org admins and owners not always being able to see hunts, queries, and runs created by other members of their team.
Fixed a data-lookup mismatch that caused entity extraction to miss data for a large share of endpoint queries.
Strengthened tenant data isolation on export and data-read endpoints.
Catalog-provided watchers are now off by default, so they no longer unexpectedly re-enable after platform updates.
Fixed queries added to an in-progress hunt sometimes being tagged with the wrong query language.
Added a clear error message instead of a crash when a hunt step references a deleted query.