Skip to main content

Hunt views and the details pane

A hunt is one tab with five views behind one switcher: Notebook, Results, Flow, Entities and Timeline. Beside the notebook, the details pane holds the hunt's outline, brief, evidence, activity and provenance. On this page you read the hunt as a graph, a grid of results, a set of entities and a timeline, and find what the details pane shows.

ViewUse it to
NotebookRead and run the steps in order. See Work in the notebook.
ResultsSearch, filter and tag every cell's rows in one grid.
FlowSee what fed what, and edit the plan as a graph.
EntitiesExplore the entities the hunt turned up.
TimelineBuild the investigation timeline.

The Flow view​

Flow draws the same cells as a graph: every step is a node, edges show what fed what, and clicking a node opens its side panel. Node cards say what a step found — 12 rows, No rows, Failed — rather than just that it ran. A dashed v2 edge links a replaced cell to its replacement.

One toolbar above the graph holds every way of reading it:

ControlWhat it does
Search nodes…, FilterFind a step by name, or narrow by node type and actor.
LegendShows what the node colours and edges mean.
EvidenceShows the entities, IOCs and tagged results each step turned up around its node.
Focus pathFocuses the graph on the selected step's path.
LanesShows the hunt's tracks as lanes. Offered when the hunt has more than one track.
Cards / CompactFull node cards, or smaller ones.
Top-down / Left-rightThe direction the graph is laid out in.

Zoom, fit and Expand graph sit in the corner of the canvas. In the Flow view, the header's Ask Scout asks Scout to review the hunt and plan the next steps.

The canvas is still the place to edit the graph: drag between nodes to set what depends on what, use Add node on a node to attach a Query, Task or Detection beneath it, and use the side panel for the full node experience. Show in notebook on a node tab jumps back to its cell; Show on canvas in the notebook goes the other way.

Read and change a step from the graph​

  1. Click a node. Its side panel opens with the step's query, results and activity.
  2. Click Show in notebook on the node's tab to jump to its cell. Show on canvas in a cell's ⋯ menu goes the other way.
  3. To add a step beneath a node, use Add node on it and pick Query, Task or Detection.
  4. To change what depends on what, drag from one node to another.

The Results view​

Results is the full grid of every cell's rows: a source rail with All results and one entry per cell, free-text search, Tagged only, Group by, row detail and export. Right-click a row to tag it, add a note or Add to timeline… — see Tags and notes and Investigation timeline. Open in Results from a cell lands here with that cell selected. Rows from discovery cells and archived cells are hidden by default; Show scaffold and Show archived bring them back.

Find and tag rows in Results​

  1. Pick All results in the source rail, or one cell to see only its rows.
  2. Narrow the grid with the search box, Tagged only or Group by.
  3. Click a row for its detail, or right-click it to tag it, add a note, or Add to timeline….

The Entities view​

Entities is the hunt's entity graph, with the entity's panel on the right. See Entities.

The Timeline view​

Timeline is the hunt's investigation timeline: the events you decided matter, oldest first, in UTC, each linked to its evidence. Add events from result rows, entities and endpoints, by hand, or with Suggest from tagged evidence, and export them with Export tracker spreadsheet. See Investigation timeline.

The details pane​

The notebook's right pane has five tabs. Resize it from its left edge. The Hide details button at the end of its tab row hides it, and Show details in the notebook header brings it back, with the number of items waiting for you. A tab with nothing in it yet, such as Evidence on a new hunt, is disabled and says why.

TabContents
OutlineOne row per cell with its outcome, and the sections between them. Click a row to jump. Beneath it, Needs you lists what is waiting — failed cells, checkpoints, approvals, the verdict — in notebook order, with the verdict last, and Next to walk through them. Checkpoints can be approved from the list with Approve step. A query, collection, task or detection Scout proposed can be approved there with the same button as on the cell. A query that still needs parameters shows Fill in parameters, and an action or endpoint proposal shows Review; both take you to the cell.
BriefThe hunt's framing: the hypothesis and findings block, a Description, the hunt's Notes, and — for hunts Scout drove — a Scout Summary with Continue in chat. Scout writes the summary from the hunt's own cells: its hypothesis, queries and row counts, notes and verdict. Notes here are about the hunt as a whole; see Tags and notes.
EvidenceEverything tagged in this hunt: tagged rows, tagged entities, labels and IOCs. Tags Scout suggested appear only after you accept them.
ActivityA timeline of what happened, in order.
ProvenanceWhere the hunt came from — Owner, Scope, Team, Planned in, Sources, Template, and for watcher-started hunts a What fired this block — plus labels, linked context and Seed Signals.

On narrower screens the pane opens as a sheet from the Details button.

Hide and show the pane​

  1. Click Hide details at the end of the pane's tab row. The notebook takes the full width.
  2. To bring it back, click Show details in the notebook header. The count beside it is the number of Needs you items.
  3. Drag the pane's left edge to resize it.

Next steps​