Skip to main content

Query templates

Query templates are saved, reusable queries — from Huntbase's built-in catalogue, from content packs that ship with your connections, or saved by your team from the query workspace. You browse them in the Library, run them straight into an Explorer query tab, and schedule them to run on their own.

Library on the Queries facet: facet rail, filter chips, template cards

The Library facet rail​

The rail on the left of the Library switches between content types:

FacetContents
Hunt playbooksReusable hunt definitions (the default view) — see Hunt playbooks
QueriesQuery templates — this page
All contentEverything in the Library together

Deep links keep the facet: /library?type=query opens the Queries facet, /library?type=playbook the playbooks. ?template_id=<id> opens a specific template's detail panel — the same link the query workspace uses for View in Library.

Browse and filter templates​

Select the Queries facet. Use the search box in the top bar (Search the library…) and the filter chips beneath it:

ChipOptions
All productsOne or more products the template runs against
TagsStructured tags from your organization's and your personal vocabularies
With a connectionDefault. Shows only templates that can run in your current scope. Choose Include all templates to see everything; the applied token reads Incl. without connection
More filtersOpens the advanced filter panel below

More filters groups:

GroupNarrows by
CategoryCategory tags (for example inventory or detection)
LanguageSQL, SQLite, SQL (Steampipe), KQL, SPL, ES|QL, osquery, Cypher, Sigma, YARA, STIX
OwnerThe user or organization that owns the template; Huntbase-owned entries are marked (Huntbase)
PlatformTarget platform for osquery templates
ParametersHas parameters / No parameters
Entity typeThe entity types the template extracts

Every applied filter appears as a token above the results (Product, Tag, Category, Language, Owner, Platform, Entity, …); remove one by clicking its ×, or use Clear these filters in the panel to reset the advanced group. The count line shows how many templates match ("Showing 40 of 312 templates") and the card / list toggle switches layouts.

What a card shows​

BadgeMeaning
TagsUp to two tags, with a +N overflow
Language / frameworkThe query language, or estate check / entity graph for graph-backed templates
N runs · 30dDistinct runs in the last 30 days
ProductsIcons for the products the template targets
Parameter badgeNumber of parameters; highlighted with N req when some are required
N entitiesHow many entity types the template extracts
inactiveThe template has been deactivated by its owner

Open a template​

Click a card to open the template detail panel. The primary button in the header is Run in explorer (see below); for query templates the panel has three tabs:

TabWhat you find
DetailsInformation (Language, Owner, Author, Version, Source link, Created, Updated, Products, Platforms, Status), Tags with an Add tag picker, Parameters with their types and defaults, Entities Extracted, Answers questions, and the query Content
UsageRuns, Success rate and Last used, plus a Recent runs list — click a run to open its results in Explorer
SchedulesSchedules attached to this template, with New schedule — see Schedules

Template detail panel on the Details tab, with the Run in explorer button and the Usage / Schedules tabs

Run a template​

  1. Open the template and click Run in explorer.
  2. Huntbase opens a new query tab in Explorer with the template loaded and the connection picker already open.
  3. Pick the connection to run against, fill in any parameters, and run.

If none of your connections match the template's products in your current scope, Run in explorer is disabled and the tooltip explains: "This template has no configured connections in the current scope." Add a connection or switch scope in the Scope selector; switch the connection chip to Include all templates to see what you're missing.

The run is recorded in the template's Usage tab and in the Activity Feed › Queries. See Query workspace.

Add a template to a hunt​

Inside a hunt, the dock's Library view leads with Suggested for this hunt — templates ranked for the hunt's subject, entities and IOCs, each showing how many hunts use it — followed by the full template list with search. Add to hunt on any template creates a cell from it in the hunt's notebook, opened for editing. The notebook's From Library… and the header's Add from Library… open the same picker. See Hunts.

Estate checks and entity-graph queries​

Some templates don't need a connection at all: Huntbase answers them from your entity graph. The panel calls this out ("Huntbase answers this one from your entity graph — no data connection to configure and no query to write") and hides the query content, because there is nothing for you to edit.

KindHeader labelButton
Estate check (graph fan-out) — an estate-wide question such as "which hosts have no endpoint agent"Estate check — graph fan-outRun estate check
Entity-graph query — a graph question scoped to particular entitiesEntity graph queryRun on entity graph

Estate checks sample your estate, so their results state how much of it they covered. Where a template declares what it covers, the Covers section lists its hypothesis categories; an estate check's optional knobs appear under Tuning (optional) rather than Parameters. Neither kind has Usage or Schedules tabs.

Create a template​

From the Library​

  1. Open the New split button and choose New query (the button's default action).
  2. The Run to Explorer wizard opens on the Custom tab of its Source step. Write your query, then continue through Configure and Review.
  3. On Review, click Save as template to save it before or instead of running.

From the query workspace​

After a query has run in Explorer, open the results ⋯ menu and choose Save as template. Give it a Name, Description and Tags, set the Supported Platforms and Parameters, and check the Body preview. See Query workspace.

Edit, tag and manage templates​

  • Owners — a template belongs to the user or organization that saved it (shown as Owner in Details). Only owners can edit a template's name, description and questions in Edit template; templates from Huntbase's catalogue are read-only.
  • Tags — add or remove structured tags from the Tags section of the Details tab (Add tag › search, New tag… or Browse folders…). Tag vocabularies are managed under Settings › Personal › Tags and your organization's Tags settings.
  • Content packs — product-specific templates arrive with your connections; see Connections.

Next steps​