Skip to main content

Tracker spreadsheet

The tracker spreadsheet exports a hunt as an Excel workbook for tracking an incident. It has one master timeline, then a tab for each kind of artifact: systems, malware and tools, accounts, network indicators, exfiltration, evidence, action items and notes. Every time is in UTC. Hand it to an incident responder, attach it to a ticket, or keep working in it after the hunt is closed.

The layout is the familiar incident-response tracker: a master timeline, then normalized tabs for systems, accounts, indicators and evidence, with the tab names, column names and status vocabulary responders already know.

Export the workbook​

Open the export from any of these places:

  • The hunt header's ⋯ menu: Export tracker spreadsheet (.xlsx)…
  • Export tracker spreadsheet in the hunt's Timeline view
  • Export… in the hunt's Results view
  • Export tracker spreadsheet… on a report row in the Activity Feed's Reports view
OptionWhat you get
Format › Tracker spreadsheet (.xlsx)The full workbook described below.
Format › Result rows only (.csv)A flat CSV of the hunt's tagged rows, with no other sheets. CSV always exports tagged rows only.
Tagged rows and entities only (ticked)Only the evidence you flagged during the hunt.
Tagged rows and entities only (unticked)The same workbook plus one Raw — step sheet for every query step, with all of that step's rows. A very large step is cut off, and its sheet says how many rows it holds.

| Save a snapshot (unticked) | The default. The workbook is built and downloaded, and Huntbase keeps no copy. | | Save a snapshot (ticked) | Huntbase also stores this workbook on the hunt, so you can download exactly this file again later. Give it an optional Snapshot label, such as Handover to IR lead. See Snapshots. |

Click Export (Save & export when Save a snapshot is ticked). The file is named after the hunt, with the time it was built. The export menu stays available on a closed hunt.

What's in the workbook​

TabWhat it holds
SummaryThe case block: Case ID, Client, Engagement start (UTC) and Summary. Then the hunt: title, hypothesis, verdict, severity, status, owner, hunt lead, ATT&CK techniques, when it opened and closed, the activity window, and the export scope. Then counts for every tab, a colour legend, and how status is decided.
TimelineThe master timeline. Every event from the hunt's investigation timeline (Source = Curated), plus timestamped tagged rows you haven't put on it yet (Source = Tagged evidence, Followup = Y). Columns: Date/Time (UTC), End (UTC), Type / ATT&CK tactic, Event System ⇄ Remote System, Account, Technique, Event, Evidence source, Confidence, Visual?, Followup, Attribution, Owner, Notes, Source.
Investigated SystemsHosts from device entities, from the timeline's System field and from host columns in tagged rows. Each has its Verdict, First Compromise (UTC), first and last activity, how many timeline events and evidence rows mention it, accounts seen, Analysis req? / Analysis status and Analyst.
Malware & ToolsFiles, hashes, processes and registry artifacts from entities and tagged rows: Filename, Path on Disk, Host, Hash, Verdict, Is IOC.
Compromised AccountsAccount Name, Account Domain, SID, Verdict, Context, first and Last Activity (UTC), systems seen, Privileges.
Network IndicatorsIPs, domains and URLs: IP, Domainname, URL / Other, Port, Verdict, Is IOC, Context, activity times, # Timeline hits. Addresses come from tagged entities, from source and remote IP columns of tagged rows, and from the timeline's addresses.
ExfiltrationTimeline events with an exfiltration tactic, and rows tagged Data Exfiltration: Staging System, Original System, Exfiltrated to, Filename, Size, Contents.
EvidenceThe evidence tracker: each data-gathering step that completed, with Date Acquired (UTC), Type, Name, Description and Location.
Action ItemsWhat's still open: tasks and checkpoints, steps that haven't run or failed, and rows tagged for follow-up (Investigate, Pending Action). Status is a dropdown: Open, In progress, Blocked, Done.
Case NotesEvery note made in or about the hunt: on rows and cells, on the hunt, and on entities, endpoints and graph nodes the hunt's evidence or timeline points to. Each note has its author, what it was on, and the field and value.
InvestigatorsThe hunt lead and everyone who tagged, noted or added to the timeline.
Tagged RowsEvery tagged result row with all of its data, its tags and who tagged it.
Other EntitiesTagged or IOC entities that fit no other tab. The tab only appears when there are any, so nothing you tagged is ever dropped.
LabelsThe hunt's own labels.
Raw — stepOnly when Tagged rows and entities only is unticked: one sheet per query step, with all of its rows.

Tracker columns that Huntbase has no data for, such as Attribution, Whois or Date Due, are kept as empty, filterable columns for you to fill in.

How status is decided​

Systems, accounts, indicators and evidence rows each get a Verdict. The strongest signal wins:

VerdictColourSet by
CompromisedRedA Compromised or IOC · Confirmed tag (or Confirmed / Malicious / True Positive), or a Confirmed timeline event that names it
SuspectedAmberA Suspicious or Investigate tag, a Threat Indicators tactic tag (C2 Beacon, Lateral Movement…), or a Suspected timeline event
ClearedGreenA Known Good, False Positive or Reviewed tag
Under investigationNoneIn scope, with no verdict yet

On the Timeline sheet, rows are coloured by Confidence the same way. Confirmed rows are red, suspected amber, and false positives grey. Visual? is Y for confirmed events, which marks them for a visual timeline.

Verdict, status and confidence cells are dropdowns, and the colour follows your edits. Change a system from Suspected to Cleared in Excel and the row turns green. The spreadsheet is yours to keep working in.

Working in the file​

  • Every sheet has a bold header row that stays in place as you scroll, plus filters on every column. Wide sheets also freeze their first column.
  • Times are real Excel date-times (yyyy-mm-dd hh:mm:ss, UTC), so they sort and filter as dates.
  • An empty tab still has its headers and a one-line hint that nothing has been recorded yet, ready for you to add rows.

To get more out of the workbook, put the story on the investigation timeline and tag the systems, accounts and addresses themselves, not just the rows that mention them.

Snapshots​

An export is built from the hunt as it is when you click, and by default nothing is stored: the workbook goes straight to your browser. When you need to keep a copy, for a handover, a ticket or alongside a report you're sending, save a snapshot. A snapshot is the workbook exactly as it was built, kept on the hunt until you delete it.

You can save one in three places:

  • Save a snapshot in the export dialog. Add an optional Snapshot label and click Save & export. Huntbase stores the workbook and downloads the stored file.
  • Save snapshot now on the Snapshots tab of the hunt's Report tab (Versions & snapshots) or of a report in the Activity Feed. Pick an optional Label and the Contents: Tagged evidence or All results.
  • Also save a spreadsheet snapshot next to Generate Report or Regenerate on the hunt's Report tab. The snapshot is taken when you click, labelled With report vN, and paired with the report version it was taken for. See Hunt reports.

The Snapshots tab lists every snapshot of the hunt, newest first, with its label (or file name), its contents, its size, the report version it was taken with, when it was saved and by whom. From there you can:

  • Download any snapshot. You get the stored file, not a fresh export, so it matches what was handed over.
  • Delete a snapshot. Delete this snapshot? asks you to confirm, and the stored workbook is removed permanently. The hunt's evidence is untouched, and you can export a fresh workbook at any time. The person who saved a snapshot can delete it, as can the hunt's owner and organization admins.

Snapshots follow the hunt's access. Anyone who can see the hunt in the active scope can list and download its snapshots, and nobody else can. Saving one needs edit access to the hunt; on a sample hunt, anyone who can see it can save one. Snapshots of sample data hunts are removed with the sample data.

Next steps​