Record a verdict and close
A hunt ends with a verdict: what you found, and why you think so. On this page you record the verdict, close the hunt, reopen or archive it, export and reuse it, and write the report.
Record a verdict
The Verdict cell sits last. It shows the current outcome line, the four verdicts as buttons, a one-line rationale, and the Verdict log beneath:
| Verdict | Meaning |
|---|---|
| Confirmed | Adversary activity found. Needs at least one cell with results as its basis. A finished endpoint check that returned rows counts. |
| Nothing found | Coverage confirmed, hypothesis ruled out. Blocked while a flagged row is still unreviewed. |
| Inconclusive | Could not test. Records the gap as a finding. |
| False positive | The triggering insight was noise. |
To record one:
- Scroll to the Verdict cell at the end of the notebook, or click the verdict under Needs you.
- Pick Confirmed, Nothing found, Inconclusive or False positive.
- Type a one-line rationale (One line on why — required). Both buttons stay off until it has text.
- Click Record & close hunt to record and close in one step, or Record only to keep the hunt open.
| Button | What it does |
|---|---|
| Record & close hunt | Adds the verdict to the log and closes the hunt in one step. Enter in the rationale does the same. |
| Record only | Adds the verdict to the log and leaves the hunt open, so you can keep adding cells and record again. |
The latest entry wins and all of them remain, each with its rationale. Scout adds Draft entries as the hunt progresses ("not tested" after failures, "supported on host" after a hit) so the line is never blank. The verdicts are Confirmed, Nothing found, Inconclusive and False positive, the same four everywhere a hunt's outcome appears. Generate report and Open report live here too.
Close a hunt
You can also close from the header: Close hunt… in the ⋯ menu closes the hunt on the verdict already recorded, and it will not close while none has been — record one first.
What closing does. A closed hunt is read-only until someone who can edit it reopens it. Closing settles work still in flight: steps waiting for approval are rejected, running queries and collections stop (Stopped: the hunt was closed), and the hunt drops out of Needs you and its counts. Notes and endpoint cells are left as they are. After you reopen the hunt, you can run the stopped and rejected steps again.
After a reopen. The verdicts the hunt was closed on no longer describe the hunt you're working on, so the log marks them Superseded instead of Recorded, and the cell says superseded — hunt reopened, record a new verdict.
Close from the header
- Record a verdict first, with Record only if you're not ready to close.
- Open ⋯ in the hunt header and choose Close hunt….
- Confirm. The hunt closes on the latest recorded verdict.
Reopen a closed hunt
- Open the hunt. The read-only strip says it's closed.
- Click Reopen hunt in the strip, or in the header's ⋯ menu.
- Record a new verdict when you're done. The old ones are marked Superseded.
Reopen, archive or discard
| Action | Where | What happens |
|---|---|---|
| Reopen hunt | ⋯ on a closed hunt, or the read-only strip | The hunt is active again. The verdicts it was closed on are marked Superseded. |
| Archive hunt | ⋯ on an active hunt | Shelves the hunt. It stays readable. |
| Restore to active | ⋯ on an archived hunt | Brings it back. |
| Discard draft… | ⋯ on a draft, owner only | Deletes the draft after a confirmation. |
These are open to the owner and anyone with Can edit, except Discard draft…, which only the owner can use.
Export and reuse a hunt
| Item in ⋯ | What it does |
|---|---|
| Export YAML | Downloads the hunt as YAML. Tick Flow only for a clean, reusable structure. |
| Export tracker spreadsheet… | The incident tracker workbook. See Tracker spreadsheet. |
| Save as playbook… | Saves the hunt as a hunt playbook you can launch again. |
| Import YAML… | Adds steps from a YAML export to this hunt. |
The exports stay available on a closed hunt.
Relaunch automatically with triggers
Open ⋯ › Triggers… to Arm a trigger: pick a watcher pattern, a session mode and a severity floor, and Huntbase launches this hunt's playbook whenever that watcher fires. If the hunt is not a playbook yet, arming saves it as one first. Armed triggers are listed with their state — Armed, Needs data, Backed off — with Run now and Remove. See Watchers.
Write the report
Generate report has Scout write the hunt up against the template you pick — the Huntbase default Threat hunt report, the Incident / hunt investigation report, or your organization's own — and Open report opens it as its own tab. The report draws on the hunt's results, entities, tags, notes and investigation timeline. Caveats such as a draft report on an open hunt, or claims the evidence doesn't support, are shown above the body. Download saves it as a Word document (.docx) or Markdown (.md), and Regenerate rewrites it after the hunt has moved on. See Hunt reports.
Next steps
- Hunt reports — templates, caveats and downloads
- Hunt playbooks — launch this hunt again later
- Pulse — where outcomes roll up