The open threat-hunting platform

Find what wasnever logged.

For lean SOC, threat hunting and IR teams: search your data, ask the host, approve every step Scout takes.

EXPLORER · HUNT H-118 · COLLABORATOR MODEEXAMPLE DATA

02Close the visibility gaps

When the log was never collected, ask the host.

History from your stores. Live answers from hosts and apps for what was never kept. One result.

STORED

  • Your lakeauthentication · 180d
  • Huntbase storageOCSF · network, http
  • SIEM archiveSPL · retained

LIVE

  • WKS-2231process list · loaded modules
  • Oktaactive sessions
  • CrowdStrike Falcondevice state
ONE ANSWER

09:41 SAML from outside egress (stored) → 09:43 unsigned DLL loaded on the host (live) → hunt opened.

03Scout

An AI partner
you can trust.

KNOWS
Reasons from your environment and Huntbase's intelligence together, not from a generic model.
SHOWS
Every answer carries the query it ran and the source it came from.
CITES
Grounded: Scout cites the evidence behind each claim and flags any claim it can't support.
WAITS
Stops at the checkpoints you set. Nothing changes on a host until two people sign off. Signed scripts, staged rollout, every step audited.Response actions: early access
LOGS
Every action it takes is in the audit log, with the version of the rule it used.

INITIATIVE

  • Ask first
  • Balanced
  • Proactive

Your analysts in command.

See Scout work a real hunt.

Watch it query stored history, ask a host, and stop for approval. Or walk through it with us on your own use case.

WKS-2231m.reyesOktaSRV-DB-04203.0.113.9T1550.004upd.dllCVE, today

NEW RISK SURFACED

SRV-DB-04 runs software named in a CVE published this morning. Hunt proposed from playbook Exposed service, new CVE.

04Understanding that compounds

Every investigation makes the next one smarter.

Every hunt, alert and incident adds to a picture of your environment, joined to Huntbase's intelligence. Scout proposes the next hunt from it, findings become Sigma watchers you backtest against your own history, and your team picks up where the last hunt left off.

  • Your findings
  • Your telemetry
  • ATT&CK
  • CVE · KEV · EPSS
  • IOC feeds
  • Shared with your team

Open by design

Your hunts and detections stay portable.

  • hunt.md, an open spec

    The hunt format Huntbase reads and writes is a public specification on GitHub.

    Read the spec(opens in a new tab)
  • 240+ published hunt playbooks

    Public on the Huntbase Hub. Take any playbook into your own hunts.

    Browse the Hub(opens in a new tab)
  • Standard formats in and out

    Detections in Sigma, telemetry in OCSF, intelligence in STIX, playbooks in CACAO.

  • Sigma
  • OCSF v1.3
  • STIX 2.1
  • CACAO v2
  • KQL
  • MITRE ATT&CK

Built by hunters, for hunters.

Practitioners building the platform they wished they had.

Our team previously worked at…

MandiantCrowdStrikeEclecticIQCiscoMcAfeeTanium
Meet the team

Your data.
Your knowledge.
Your call.

Search what you already have, ask the host when it was never collected, and approve every step Scout takes. Sign up and start on sample data today.

  1. 01Sign up
  2. 02Run a guided hunt on the sample workspace, no connector needed
  3. 03Connect your own sources when you're ready