Skip to main content

Threats

The Threats tab (Intelligence › Threats) lists the adversaries and tooling your intel knows about: threat actors, malware, campaigns and reports. They come from MITRE ATT&CK groups and software, and from the STIX objects in the feeds your organization can read. Each threat carries a relevance score for your organization, so you can see which ones matter to you and where your detections have gaps.

Beta

Threats is part of Intelligence, which is in beta. Access is by request, so it may not be enabled for your organization.

Find a threat​

  • Kind tabs: All, Actors, Malware, Campaigns or Reports.
  • Relevant to us: shows only threats that score 30 or more for your organization, most relevant first.
  • Search: matches names, aliases and ATT&CK ids, such as Scattered Spider, UNC3944 or G1015.

Each row shows the threat's name, kind, ATT&CK ids and aliases, the top reason it's relevant, and how many techniques (and how many of them you don't cover), indicators and reports are linked to it. Load more fetches the next page.

The kind, the switch and the search are kept in the page address, so you can bookmark or share a filtered list.

Relevance​

The relevance score runs from 0 to 100. Huntbase works it out from three things it already knows about your organization:

FactorWeightWhat counts
Targeted products50%Products the threat is known to target that you have connected, for example Okta, Entra ID or AWS.
Owned vulnerabilities30%Known-exploited CVEs the threat uses that are present on your assets.
Technique overlap20%The threat's ATT&CK techniques that your data can see.

The badge shows the score with a band: High (70 and above), Medium (40 to 69) or Low (below 40). Hover over it, or focus it with the keyboard, to read the main reason. A threat with no score shows Not scored.

When a threat scores 60 or more for your organization, the Threat relevant to your environment watcher can notify you or start a hunt, at most once a week for each threat. See Watchers.

Threat details​

Select a threat to open its details on the right. The link in the address bar opens the same threat for anyone you share it with, as long as they can see it.

  • Why it's relevant: the reasons behind the score, the products you use that it targets, and the CVEs on your assets it exploits.

  • ATT&CK techniques: every linked technique with your coverage, gaps first:

    • Not covered: no live detection and no hunt;
    • Hunt only: a hunt looks for it, but no live detection;
    • Live detection: a rule that is on covers it;
    • Live · needs data: a rule that is on covers it, but you don't send the data it needs yet, so it can't fire.

    Each technique links to its page on attack.mitre.org.

  • About: the threat's description.

  • Indicators: up to 20 indicators linked to the threat. Select one to open it. For actors and malware, View all opens Indicators filtered to that actor or malware.

  • Reports: reports that mention the threat. Select one to open it.

Find detections​

Find detections opens Detections filtered to the threat's techniques, with the uncovered ones first. Use it to check which rules you already have and which ones to turn on or write.

Generate hunt​

Generate hunt opens a Scout chat in the Explorer with a prompt already written: hunt for this threat, focusing on the techniques you don't cover. The prompt isn't sent until you send it, so you can edit it first. It contains only the threat's name, ATT&CK ids and technique ids, never the text of a private report.

If hunts aren't enabled for your organization, the button reads Browse hunt playbooks and opens the hunt playbooks in the Library.

Who sees what​

Threats from shared sources such as MITRE ATT&CK are visible to every organization. Threats and reports from your organization's private feeds are visible only to your organization. The relevance score is always your organization's own.