Skip to main content

Inbox

The Inbox holds messages addressed to you: threat intel and hunt suggestions from Scout, product updates and announcements from Huntbase, onboarding tips, and requests for information. Many messages carry an action, such as Start hunt, Ask Scout or Run in explorer, so you can act on a message without leaving it.

Open it from the tray icon in the footer of the sidebar. A red dot on the icon means you have unread messages. You can also press ⌘K / Ctrl+K and type inbox.

Your inbox is personal. It holds messages from every organization you belong to, and the Scope selector doesn't filter it. A message about one organization shows that organization's name as a chip in the list and as a badge on the message. If you leave an organization, its messages leave your inbox.

The layout​

On a wide screen the Inbox has three panes, which you can resize: folders, the message list, and the reading pane. The page header shows how many messages are unread, or All caught up.

On a narrow screen the folders become a row of buttons at the top. Opening a message replaces the list; Back to list returns to it.

Folders​

FolderWhat's in it
InboxMessages that aren't archived or snoozed. Shows the unread count.
PinnedMessages you starred.
SnoozedMessages hidden until a time you chose.
ArchivedMessages you archived or dismissed.

The message list​

Each row shows the sender, the subject, a one-line preview and when it was sent. Unread messages are bold. A pinned message has a star. A snoozed one says Snoozed until and the date. ✓ Done means you've already completed one of the message's actions.

The list loads 30 messages at a time. Click Load more at the bottom for the next page.

The toolbar above the list:

ControlWhat it does
SearchFilters by subject and preview as you type.
UnreadShows only unread messages.
TypeFilters by category: Threat Intel, Suggestions, Product Updates, Onboarding, Requests for Info, Conversations or Announcements.
Mark all readMarks every message in the folder read, within the Type filter.
RefreshFetches the latest messages. New messages also arrive on their own.

Tick the checkbox on a row, or the one at the top for the whole page, to act on several messages at once: mark them read or unread, archive (or unarchive) them, or delete them.

Reading a message​

Click a message to open it in the reading pane. It's marked read after a second. The header shows the subject, the sender, the category, the organization if there is one, and when it was sent. If the message expires, a notice says when.

Links to other Huntbase pages open in the app. A link to an outside website first opens a Leaving Huntbase dialog with the address defanged, because a link in a message hasn't been checked and may be an indicator itself. Click Open anyway to follow it, or copy the address instead.

Senders​

AvatarSender
Blue robotScout
Violet buildingHuntbase
Initials or photoA person

Act on a message​

Hover a row, or use the buttons above an open message:

ActionWhat it does
PinStars the message and adds it to Pinned.
Mark as read / Mark as unreadToggles the unread state.
SnoozeHides the message until a time you choose. See Snooze.
ArchiveMoves it to Archived. Move to inbox brings it back.
DeleteRemoves it from your inbox. From the reading pane, you confirm first. From the list or the keyboard, it's deleted straight away.

Snooze​

Choose when the message comes back:

  • Later today, in three hours
  • Tomorrow, at 9:00 AM
  • This weekend, Saturday at 9:00 AM
  • Next week, Monday at 9:00 AM
  • Pick date & time…, up to 90 days ahead

When the time comes, the message returns to the top of Inbox as unread, and you get a Snoozed message returned to your inbox toast. Snoozing a pinned or archived message moves it out of Pinned or Archived. Archiving a snoozed message cancels the snooze. To bring one back early, open Snooze and pick Unsnooze (return to inbox).

Message actions​

A message can carry action buttons, in its text or in a bar at the bottom. The sender chooses each button's label. Once you've done an action, its button changes, for example to Hunt started, Submitted or Opened. Some actions can only be done once.

ActionWhat happens
Start a huntCreates a hunt, from a playbook or from the hypothesis in the message, and opens it in Explorer. Scout drives it.
Ask ScoutOpens a Scout chat in Explorer with the message's prompt. Usually the prompt is sent at once. Some messages leave it in the chat box as a draft, for you to edit and send.
Run a queryOpens a new query tab with the query, its language and its connections filled in. It doesn't run until you click Run.
Open a pageOpens a connection, hunt, playbook, watcher, query or library item.
Continue a chatReopens an earlier Scout chat.
Fill out a formScrolls to a form in the message. See Forms.
External linkOpens a website in a new tab. The button shows an arrow.
DismissArchives the message.

A query in a message appears as a card with the query itself, its language and how many connections it uses. Click the copy button to copy the query, or the card's button to open it in Explorer.

note

When a message belongs to one of your organizations, starting a hunt, asking Scout, running a query or opening a page first switches your scope to that organization. The hunt, chat or query tab is created there.

Forms​

Some messages, such as requests for information, include a short form. Required fields are marked with *. Click the submit button to send your answers. If you open the message again, your earlier answers are filled in and you can update them.

Keyboard shortcuts​

These work while the Inbox is open and you aren't typing in a field.

KeyAction
j / kNext / previous message
eArchive or unarchive
sPin or unpin
uMark read or unread
#Delete, without confirming
rRefresh
EscClose the message

New messages​

New messages arrive while you're signed in. When one arrives, a toast shows the sender and subject, with Open to go to the Inbox. You don't get the toast while you're on the Inbox, or for low-priority messages.

The Inbox also appears in other places:

  • The bell in the page header has an Inbox tab. It lists your eight latest messages, with Mark all read and Open inbox →. Click a message to open it. Inbox messages don't count towards the bell's badge. See Notifications.
  • The Explorer home tab adds an Inbox section to the What now rail with up to three unread messages. While the rail is collapsed, the line under the greeting tells you how many new messages you have. Click it to open the Inbox.

To choose how you hear about new messages, open Settings › Personal › Notifications and use the Inbox table. You can turn off the in-app alerts for new and returning messages. Email, where you turn it on, is a short "you have a new message" nudge, sent only for messages the sender marked for email. See Notification preferences.

Next steps​

  • Notifications: the bell, and how you're told about new messages
  • Explorer: where hunts, chats and queries from a message open
  • Hunts: what happens after you start a hunt from a message