Skip to main content

Indicators

The Indicators tab (Intelligence › Indicators) is where you search the threat intel your organization receives: IPs, domains, URLs, hashes, emails, JA3 fingerprints and certificates from the feeds you subscribe to, your private TAXII and MISP connections, and your watch lists. For each indicator you can see where it came from, whether it was seen in your environment, and hunt for it back over your data.

Beta

Intelligence is in beta, and access is by request. It may not be enabled for your organization.

Search and filter​

Type a value, or part of one, in the search box and press Enter. Values match exactly or by prefix (185.220 finds 185.220.101.4). Defanged input such as hxxps://evil[.]test or 8.8.8[.]8 is refanged before searching.

Add filters as key:value tokens in the same box:

TokenExampleFilters by
type:type:ipv4,domainIndicator type: ipv4, ipv6, cidr, domain, url, md5, sha1, sha256, email, ja3, x509_sha1
source:source:et_compromised,cinsFeed, by its short name
tlp:tlp:clear,greenTLP marking
confidence:confidence:>=70Confidence 0–100. Also <=40, 40-69 or an exact number
seen:seen:30dLast seen within that window
sighted:sighted:yesSeen in your environment (yes or no)
actor:actor:"Scattered Spider"Linked threat actor. Quote names with spaces
malware:malware:"Cobalt Strike"Linked malware family
state:state:allactive (the default), expired, revoked or all
sort:sort:scorelast_seen (the default), score or first_seen, newest or highest first

For example, type:ipv4 source:et_compromised confidence:>=70 sighted:yes lists high-confidence IPs from the Emerging Threats compromised-hosts feed that were seen in your environment. The ⓘ button next to the search box lists the tokens.

The sidebar offers the same filters as checkboxes, with a count for each option. Ticking one updates the search box, and typing a token ticks the matching box. On a narrow screen the sidebar is behind the Filters button.

Filters are part of the page's address, so you can bookmark or share a filtered list, and the browser's Back button undoes a filter.

The table shows 50 indicators at a time. Select Load more at the bottom for the next 50.

What the columns mean​

  • Indicator: the value, shown defanged so it can't be clicked by accident. The copy button copies the real value.
  • Source: the feed it came from. A people icon marks a shared feed; a lock marks one private to your organization.
  • Confidence: how sure the source is, from 0 to 100.
  • TLP: the Traffic Light Protocol marking, which says how widely you may share it.
  • Context: the malware, actor or threat type the source linked it to. Expired and revoked indicators are marked.
  • Sightings: how many times it was seen in your environment, and on how many entities.
  • Last seen: when the source last reported it.

Bulk lookup​

Select Bulk lookup to check a list of values at once, for example the IOCs from an incident report or a partner's bulletin.

  1. Paste up to 10,000 values, one per line or separated by commas or spaces. Defanged values are fine, and duplicates are removed.
  2. Select Look up.
  3. Each value is marked Known (in your intel), Unknown or Invalid (not recognised as an indicator), with the best match's source and confidence and whether it was Sighted in your environment. Use the buttons above the table to show only one group.

From the result you can:

  • Export CSV: download the rows currently shown, with the source, confidence, TLP, malware, actors and sighting count of each value's best match.
  • Hunt last N days: search your telemetry for the valid values (see Hunt back over your data).
  • Save as watch list: keep watching for the valid values (see Watch lists).
  • New lookup: start again.

Indicator details​

Select an indicator to open its page. It shows:

  • Sightings: where it was seen in your environment, newest first. Each entry shows the host, user, IP or hash it was seen on, the field it matched, how it was found (Live match as telemetry arrived, Retro-hunt, or Graph match), how many times and when. Select a host, user, IP or hash to open its entity timeline around that time.
  • Pattern: the original STIX pattern, when the source sent one.
  • Related: linked actors, malware and campaigns, and the MITRE ATT&CK techniques from the indicator's kill chain. Technique chips open the technique on attack.mitre.org.
  • Provenance: the source, first and last seen, validity window, STIX id, the source's own reference, labels and markings. Also in lists other feeds that report the same value; select one to see that feed's copy.
  • Detections: the intel watchers and rules that cover this indicator, with whether each is on, in shadow or off. Select one to open it in Intelligence › Detections.

Open graph opens the indicator in the Explorer graph, when it's there.

Respond to a sighting​

When a sighting is on a host that Huntbase manages (an osquery endpoint connected through osctrl), the sighting has a Respond… button. It proposes a response action on that host: kill a process, quarantine a file or run an approved script. Isolating the host is not offered here.

  1. Select Respond… on the sighting.
  2. Choose the endpoint (if the host matches several), the action and its target (a process id, a file path or a script), and say why. The reason is filled in for you and can be edited.
  3. Select Propose action.

Nothing runs yet. A response is only a proposed action: it's added to a hunt, and it runs only after a second person approves it there. Select Open hunt to follow it. If the button says the host isn't managed, or that you aren't allowed to respond, ask a fleet admin (see Access and activity).

Hunt back over your data​

New intel often describes activity that already happened. Hunt last N days searches your telemetry for a set of indicators over a past window:

  • on the Indicators tab, select rows with their checkboxes, then select Hunt last N days;
  • on an indicator's page, select Hunt last N days;
  • from a bulk lookup result.

Choose how far back to look (7 to 90 days) and select Hunt last 30 days (the button names the window you chose). You can tick Also save as a watch list to keep watching for the same values. A hunt takes up to 10,000 values.

The dialog shows the hunt's progress and, when it finishes, how many hits it found. Hits are recorded as sightings on each indicator and go through your intel watchers like any other match. Finished with gaps means some data sources were skipped or cut short, for example because the search would have scanned too much data; the dialog lists which.

Watch lists​

A watch list is your own list of values to watch for, private to your organization. New telemetry is matched against it, and a match fires the Watch list value observed watcher at the severity you chose.

To create one, select rows (or use a bulk lookup result) and select Save as watch list. Then either:

  • choose New list, and give it a name, a severity, what to do on a match (Alert, Record sightings only or Off) and whether to hunt back over the last 7, 30 or 90 days when it's saved; or
  • choose Add to existing and pick a list.

A watch list holds up to 50,000 values. Values that aren't recognised as indicators are left out, and the confirmation says how many.

From the command palette​

With Intelligence on, picking an IP, domain, URL, hash or indicator in the command palette (⌘K / Ctrl+K) opens the Indicators tab searched for that value, instead of the Explorer graph. Hosts, users and other entities open as before.