Skip to main content

Work in the notebook

A hunt opens on its Notebook: the steps as an ordered list of cells you read top to bottom, with what each one found. On this page you add and arrange cells, run them, fill in query parameters, read their output, and archive what you no longer need.

Cells​

The notebook lists the hunt's cells in order. Each cell has a gutter on the left — a run control and an execution mark such as [3] ✓, [5] ✕ or [*] for a cell that is running — and a body with the cell's type, title, who ran it, its content, and the output of its latest run.

CellWhat it holds
HypothesisThe subject or hypothesis, with Edit, and Suggest with Scout / Regenerate with Scout to have Scout draft one. Its meta line shows the scope, owner and any IOCs.
SectionA heading that groups the cells beneath it until the next section. Scout adds one for each batch it plans or rewrites; click the title to rename yours.
QueryA query against your connections. The query text shows inline; Edit opens the same editor the query workspace uses, with Run (save then run) and Save without running.
Task, Checkpoint, Action, Detection, AnalyticThe other step types, with the same controls the Flow view offers: Approve / Mark done on a task, Approve step / Refine / Abort on a checkpoint (under Your approval is needed), and so on.
NoteFree-form markdown between cells. Note opens a draft; nothing is saved until you click Save note.
Endpoint transcriptA console session saved from an endpoint with Save to hunt: its commands, times and outcomes, shown like a terminal, with the output tables when output was included. Read-only; it never runs. See Save a console session to a hunt.
Endpoint check, Endpoint snapshot, Endpoint action, Endpoint watchWork on one endpoint from inside the hunt: a read-only query, a snapshot of what is running, a proposed response action, or a timed re-check. See Endpoint cells.
Telemetry viewA view of your shipped telemetry pinned to the hunt, with a snapshot of what it matched. See Telemetry view cells.
VerdictAlways last. See Verdicts.

Run a cell​

The gutter's run control is the cell's one run button: Run cell on a cell that hasn't run, Run cell again on one that has. On a Stale cell it turns amber, and on a failed cell red. Then it runs the cell and everything below it (Run again (and downstream)), and the cell's ⋯ menu adds Run this cell only.

To run one cell:

  1. Hover or focus the cell.
  2. Click its run control in the gutter, or press ⌘⏎ / Ctrl+⏎.
  3. Watch the gutter: it shows [*] while the cell runs, then the outcome.

To run everything that can run, use Run all in the hunt header. Steps that need approval pause it; see Approvals and Needs you.

Queries with parameters​

A query cell that hasn't run and still contains a {{parameter}} shows an input for each one. Run (or Approve & run) stays off, with a hint such as Fill in instance_name to run, until you fill them in. The values are saved with the cell and used for the run.

Edit a query cell​

  1. Hover the cell and click Edit in its header.
  2. Change the query in the editor. It's the same editor the query workspace uses.
  3. Click Run to save and run it, or Save without running.
  4. Press Esc to leave without saving.

What a cell found​

The output under a runnable cell says what happened, in one word first:

OutputWhat you see
FailedThe error, with Run again (this cell only) and Fix with Scout. Cells that failed for the same reason say same error in cell N. To change the query yourself, use Edit in the cell's header.
N rowsA preview of the first three rows, flagged rows highlighted, and Open in Results for the full grid. If the run didn't report a row count, the cell reads the first rows of the result to show the preview.
No rowsA one-line explanation. A clean run is a result, not an absence. It's only shown when the result is actually empty. If the result can't be read, the cell just says Done.
RunningA progress bar; the gutter shows [*].
Not runNothing yet. A Stale badge means something upstream changed since; the amber run control in the gutter runs the cell and everything below it.

Fix with Scout does not overwrite the failed cell: Scout writes a new cell that replaces it, badged v2 of N, and the original is marked replaced by N. Keep the original for the record or Archive it from the cell's ⋯ menu — archived cells stay in place, dimmed, and drop out of counts, Results and the Entities count (Hide archived at the top of the notebook hides them entirely). The Cell archived message has Undo, and an archived cell offers a Restore button in its header, in place of Open and Edit. Anyone who can edit the hunt can restore a cell.

Scout's discovery probes — schema lookups it ran to learn a store — fold into one strip, N cells · Discovery, with Show to open them.

Add, move and remove cells​

  • Add cell at the bottom offers Query, Note, Section, Endpoint and Telemetry view (where available), Scout cell (Scout reviews the hunt so far and adds the next step) and From Library…. Hover the gap between any two cells for a + with the first three cell types in place.
  • Hover or focus a cell for its header actions: Edit on a query cell, Open, and the cell menu (⋯). The menu offers Insert above… / Insert below…, which open a Query · Note · Section row at that spot, Move up / Move down, Show on canvas, then Archive and — for a cell that has never run — Delete…. Notes have Edit and a ⋯ with Archive and Delete…; a section's ⋯ has Delete section…; endpoint and telemetry view cells have Archive in theirs. Deleting asks first, names the cell, and removes it from the flow as well.
  • A query cell you cancel with nothing typed is removed for you. A new cell you save or run stays.
  • A new cell hangs off the step it follows, so it sits in the right place in the Flow view: after the focused cell when you insert one there, otherwise after the last step. Drill into endpoint places its cell right after the query cell it came from.
  • Open in a query cell's header opens it in a query tab that stays linked to the step. A strip above the results reads Hunt step with the step's title and Runs update this step, with Show in notebook. Edit and run the query there and the cell updates, with no duplicate step. When the cell runs again from the notebook or the Flow view, the tab shows the new run.

Add a note or a section​

  1. Click Note or Section under Add cell, or use Insert above… / Insert below… in a cell's ⋯ menu to put it at that spot.
  2. For a note, write in markdown and click Save note. Nothing is saved until you do.
  3. For a section, type its title. Click the title later to rename it.
KeysAction
j / kMove focus down / up through cells
a / bInsert a query cell above / below the focused cell
⌘⏎ / Ctrl+⏎Run the focused cell. The same keys run a query from inside the cell's editor. Outside an editor, ⇧⏎ works too.
EscLeave an edit

Next steps​