The open threat-hunting platform
For lean SOC, threat hunting and IR teams: search your data, ask the host, approve every step Scout takes.
authentication
| where status == "Success" and auth_protocol == "SAML"
| where src_endpoint.ip !in (known_egress)
| summarize count() by user.name, src_endpoint.ip, store01Who it's for
02Close the visibility gaps
History from your stores. Live answers from hosts and apps for what was never kept. One result.
STORED
LIVE
09:41 SAML from outside egress (stored) → 09:43 unsigned DLL loaded on the host (live) → hunt opened.
03Scout
INITIATIVE
Your analysts in command.
Watch it query stored history, ask a host, and stop for approval. Or walk through it with us on your own use case.
NEW RISK SURFACED
SRV-DB-04 runs software named in a CVE published this morning. Hunt proposed from playbook Exposed service, new CVE.
04Understanding that compounds
Every hunt, alert and incident adds to a picture of your environment, joined to Huntbase's intelligence. Scout proposes the next hunt from it, findings become Sigma watchers you backtest against your own history, and your team picks up where the last hunt left off.
Open by design
The hunt format Huntbase reads and writes is a public specification on GitHub.
Read the spec(opens in a new tab)Public on the Huntbase Hub. Take any playbook into your own hunts.
Browse the Hub(opens in a new tab)Detections in Sigma, telemetry in OCSF, intelligence in STIX, playbooks in CACAO.
Practitioners building the platform they wished they had.
Our team previously worked at…
Search what you already have, ask the host when it was never collected, and approve every step Scout takes. Sign up and start on sample data today.