Skip to main content

Changelog — August 3 – 16, 2026

New Features

  • Hunt playbooks import and export as hunt.md, and CACAO playbooks can be imported, so a playbook can be reviewed, versioned and shared outside Huntbase.
  • Ask Scout about the entity graph. Open a graph and ask a question about what is on the canvas without leaving it; chips now seed a graph rather than a search.
  • A "what now" worklist on the Explorer landing surface, so opening Explorer starts with what is worth working on rather than an empty tab.
  • Map view for query results. Results with geographic fields render on a real map, alongside the table, chart and other shape-aware views.
  • Results can stay pinned open beside any view, so you can read the rows and a chart at the same time.
  • Graph fan-outs run from the Library as estate checks — a question asked across your estate — instead of being forced into the shape of a query.
  • A searchable filter panel in the Library, with filters for language, owner and platform.
  • Template-driven hunt reports, plus an organization report-template editor, so reports come out in your own format. Scout shows a report card when it queues one.
  • A Template tab in the query details panel, showing the template a run came from.
  • Insights show where they came from. Watcher-raised insights and hunts name the watcher that raised them, and the Activity Feed can filter by origin and triage state on the server.

Improvements

  • The Activity Feed is built for auto-hunt scale: server-side sort and origin/triage filters, campaign roll-ups from the server, multi-select type filters, a board view of the whole pipeline, collapsed concluded columns, and archiving a hunt or query from the list it appears in.
  • Honest result counts. Query results now say what they actually measured — including when a scoped filter is why a result is empty — rather than presenting a number that reads as complete.
  • One query workspace. Query, hunt and graph tabs now share one frame, one query bar and one panel mechanism; panel open/close behaves the same everywhere; tabs are coloured by subject and say how your query was read.
  • The hunt canvas became a workspace: clicking a step opens its query in the viewport, you can ask a question without leaving the hunt, node detail lives on the shared panel, and there is one clear first action on an empty hunt.
  • Outbound links are checked against a trust policy before they open, including links derived from event data.
  • Entities: account and user are now separate entity types, named-object lists render as chips instead of raw JSON, and the entity detail panel matches the insight panel.
  • Discovered schemas explain themselves. On a dynamic-schema connection, table descriptions can be edited (badged User Modified, with Discard user edits to revert), and discovery errors are shown on the connection and on the table that failed.
  • Provider coverage is driven by what is actually available, not by what a definition claims.
  • Restoring a closed Explorer tab restores one tab, not two, and ?graph= works when Explorer is already open.
  • Upgraded to React 19.

Bug Fixes

  • Fixed hunts counting entities they were tagged with rather than the ones they observed.
  • Fixed the Activity Feed showing organizations under "Run by" instead of the person who ran it.
  • Fixed the feed fabricating a severity and status for insights that had none.
  • Fixed Cypher query templates being gated on having a connection, which they don't need.
  • Fixed graph canvases showing tenancy edges, and finding nodes going unlabelled.
  • Fixed tags being requested for resources the API cannot address.
  • Fixed the docked Scout chat losing its chain of thought, and hunt-panel navigation from the dock.
  • Fixed Scout resource references not resolving on historical runs.
  • Fixed detail-panel titles truncating identifiers.
  • Fixed creating a hunt from the top navigation not routing to Explorer.
  • Fixed an edited query re-running in place instead of opening its own tab.