Hunt playbooks import and export as hunt.md, and CACAO playbooks can be imported, so a playbook can be reviewed, versioned and shared outside Huntbase.
Ask Scout about the entity graph. Open a graph and ask a question about what is on the canvas without leaving it; chips now seed a graph rather than a search.
A "what now" worklist on the Explorer landing surface, so opening Explorer starts with what is worth working on rather than an empty tab.
Map view for query results. Results with geographic fields render on a real map, alongside the table, chart and other shape-aware views.
Results can stay pinned open beside any view, so you can read the rows and a chart at the same time.
Graph fan-outs run from the Library as estate checks — a question asked across your estate — instead of being forced into the shape of a query.
A searchable filter panel in the Library, with filters for language, owner and platform.
Template-driven hunt reports, plus an organization report-template editor, so reports come out in your own format. Scout shows a report card when it queues one.
A Template tab in the query details panel, showing the template a run came from.
Insights show where they came from. Watcher-raised insights and hunts name the watcher that raised them, and the Activity Feed can filter by origin and triage state on the server.
The Activity Feed is built for auto-hunt scale: server-side sort and origin/triage filters, campaign roll-ups from the server, multi-select type filters, a board view of the whole pipeline, collapsed concluded columns, and archiving a hunt or query from the list it appears in.
Honest result counts. Query results now say what they actually measured — including when a scoped filter is why a result is empty — rather than presenting a number that reads as complete.
One query workspace. Query, hunt and graph tabs now share one frame, one query bar and one panel mechanism; panel open/close behaves the same everywhere; tabs are coloured by subject and say how your query was read.
The hunt canvas became a workspace: clicking a step opens its query in the viewport, you can ask a question without leaving the hunt, node detail lives on the shared panel, and there is one clear first action on an empty hunt.
Outbound links are checked against a trust policy before they open, including links derived from event data.
Entities: account and user are now separate entity types, named-object lists render as chips instead of raw JSON, and the entity detail panel matches the insight panel.
Discovered schemas explain themselves. On a dynamic-schema connection, table descriptions can be edited (badged User Modified, with Discard user edits to revert), and discovery errors are shown on the connection and on the table that failed.
Provider coverage is driven by what is actually available, not by what a definition claims.
Restoring a closed Explorer tab restores one tab, not two, and ?graph= works when Explorer is already open.