Skip to main content

Record a verdict and close

A hunt ends with a verdict: what you found, and why you think so. On this page you record the verdict, close the hunt, reopen or archive it, export and reuse it, and write the report.

Record a verdict​

The Verdict cell sits last. It shows the current outcome line, the four verdicts as buttons, a one-line rationale, and the Verdict log beneath:

VerdictMeaning
ConfirmedAdversary activity found. Needs at least one cell with results as its basis. A finished endpoint check that returned rows counts.
Nothing foundCoverage confirmed, hypothesis ruled out. Blocked while a flagged row is still unreviewed.
InconclusiveCould not test. Records the gap as a finding.
False positiveThe triggering insight was noise.

To record one:

  1. Scroll to the Verdict cell at the end of the notebook, or click the verdict under Needs you.
  2. Pick Confirmed, Nothing found, Inconclusive or False positive.
  3. Type a one-line rationale (One line on why — required). Both buttons stay off until it has text.
  4. Click Record & close hunt to record and close in one step, or Record only to keep the hunt open.
ButtonWhat it does
Record & close huntAdds the verdict to the log and closes the hunt in one step. Enter in the rationale does the same.
Record onlyAdds the verdict to the log and leaves the hunt open, so you can keep adding cells and record again.

The latest entry wins and all of them remain, each with its rationale. Scout adds Draft entries as the hunt progresses ("not tested" after failures, "supported on host" after a hit) so the line is never blank. The verdicts are Confirmed, Nothing found, Inconclusive and False positive, the same four everywhere a hunt's outcome appears. Generate report and Open report live here too.

Close a hunt​

You can also close from the header: Close hunt… in the ⋯ menu closes the hunt on the verdict already recorded, and it will not close while none has been — record one first.

What closing does. A closed hunt is read-only until someone who can edit it reopens it. Closing settles work still in flight: steps waiting for approval are rejected, running queries and collections stop (Stopped: the hunt was closed), and the hunt drops out of Needs you and its counts. Notes and endpoint cells are left as they are. After you reopen the hunt, you can run the stopped and rejected steps again.

After a reopen. The verdicts the hunt was closed on no longer describe the hunt you're working on, so the log marks them Superseded instead of Recorded, and the cell says superseded — hunt reopened, record a new verdict.

Close from the header​

  1. Record a verdict first, with Record only if you're not ready to close.
  2. Open ⋯ in the hunt header and choose Close hunt….
  3. Confirm. The hunt closes on the latest recorded verdict.

Reopen a closed hunt​

  1. Open the hunt. The read-only strip says it's closed.
  2. Click Reopen hunt in the strip, or in the header's ⋯ menu.
  3. Record a new verdict when you're done. The old ones are marked Superseded.

Reopen, archive or discard​

ActionWhereWhat happens
Reopen hunt⋯ on a closed hunt, or the read-only stripThe hunt is active again. The verdicts it was closed on are marked Superseded.
Archive hunt⋯ on an active huntShelves the hunt. It stays readable.
Restore to active⋯ on an archived huntBrings it back.
Discard draft…⋯ on a draft, owner onlyDeletes the draft after a confirmation.

These are open to the owner and anyone with Can edit, except Discard draft…, which only the owner can use.

Export and reuse a hunt​

Item in ⋯What it does
Export YAMLDownloads the hunt as YAML. Tick Flow only for a clean, reusable structure.
Export tracker spreadsheet…The incident tracker workbook. See Tracker spreadsheet.
Save as playbook…Saves the hunt as a hunt playbook you can launch again.
Import YAML…Adds steps from a YAML export to this hunt.

The exports stay available on a closed hunt.

Relaunch automatically with triggers​

Open ⋯ › Triggers… to Arm a trigger: pick a watcher pattern, a session mode and a severity floor, and Huntbase launches this hunt's playbook whenever that watcher fires. If the hunt is not a playbook yet, arming saves it as one first. Armed triggers are listed with their state — Armed, Needs data, Backed off — with Run now and Remove. See Watchers.

Write the report​

Generate report has Scout write the hunt up against the template you pick — the Huntbase default Threat hunt report, the Incident / hunt investigation report, or your organization's own — and Open report opens it as its own tab. The report draws on the hunt's results, entities, tags, notes and investigation timeline. Caveats such as a draft report on an open hunt, or claims the evidence doesn't support, are shown above the body. Download saves it as a Word document (.docx) or Markdown (.md), and Regenerate rewrites it after the hunt has moved on. See Hunt reports.

Next steps​