Ask the Endpoint: osquery as Huntbase's Truth Layer Product

Ask the Endpoint: osquery as Huntbase's Truth Layer

Logs record what a system chose to report. osquery answers what the machine looks like right now. How Huntbase turns live endpoint truth into a core layer of every hunt.

@Ravindra Bangrawa 9/8/2026
The ECB told banks to build AI-enabled defence. It didn't say what that means. Security

The ECB told banks to build AI-enabled defence. It didn't say what that means.

The ECB's July letter asks 110 banks for an action plan by 31 October. Its annex spends paragraphs on patching, attack surface and governance, and one line on "AI-enabled defensive capabilities." That blank space will define the benchmark. Here's what we think belongs in it, and why it isn't alert triage.

@Tyler 9/1/2026
Scout's Agent Architecture: One Brain, Many Firewalls Product

Scout's Agent Architecture: One Brain, Many Firewalls

Swapping in a smarter model doesn't make an agent useful at 2 a.m. during an incident. The harness does. Here's how we built Scout's: a single reasoning agent instead of a swarm, sub-agents as context firewalls, graph RAG that walks instead of reads, and watchers that keep a hunt alive for months at near-zero cost.

@Rakesh Mukherjee 8/24/2026
Announcing hunt.md: an open, portable format for threat-hunting playbooks Product

Announcing hunt.md: an open, portable format for threat-hunting playbooks

Introducing hunt.md — an open Markdown format that turns threat hunts into readable, reviewable, executable documents. Vendor-neutral, agent-ready, and MIT-licensed.

@Tyler 8/14/2026
Product

Hunting Doesn't Stop at Live Data: Introducing Federated Data-at-Rest Search

Huntbase now searches data at rest. Bring your own acquired data — log exports, evidence collections, telemetry that never made it into your SIEM — and hunt across it alongside live systems and cloud sources like AWS, all in one federated query, all driven by Scout's intelligence-led guidance. Live and historical, one hunt.

@huntbase 7/28/2026
When the attacker runs at machine speed Security

When the attacker runs at machine speed

The first well-documented intrusion run end to end by an AI didn't rely on a new kind of weakness. It walked through old ones at machine speed. What that changes for defenders: controls decide the blast radius, but continuous hunting is what keeps pace with attacks that now arrive faster and more often.

@Tyler 7/22/2026
Security

The Hunting Imperative: Why AI Shifts the Battlefield Deeper

Tyler Oliver and Richard Olver attended BSides San Francisco and RSA 2026, and the mood was telling. The community is nervous — not just about the adversary, but about its own future. AI is lowering the cost of initial compromise to near zero while post-compromise operations grow quieter and more sophisticated. The AI SOC market promises answers but is still wrestling with trust, integration gaps, and investigations that sprawl beyond any single tool's reach. This is not a piece about despair. It is about where the line actually holds — and why the people doing the hard work of threat hunting matter more now than they ever have.

@Tyler Oliver and @Richard Olver 3/30/2026
Inside the Quiet Work of Threat Hunting Security

Inside the Quiet Work of Threat Hunting

The term "threat hunting" spread across conference booths and job descriptions long before anyone agreed on what it meant. Marketing teams liked it because it sounded active. Executives liked it because it implied a stronger posture. But the work itself never changed. It was always structured investigation, patient and evidence-driven, practiced long before anyone tried to brand it. The discipline deserves clarity. Without a framework, hunting is just a label that hides inconsistent practice.

@Jeff Hamm 3/17/2026
Why We Will Probably Always Need Human ‘Threat Hunters’ Security

Why We Will Probably Always Need Human ‘Threat Hunters’

Close to midnight. Automated triage finished. Queue empty. Most of the team signed off. But a few scattered events didn't fit the rhythm of the environment. A login slightly earlier than usual. A process tree that was too tidy. Commands issued too close together. Nothing alarming on its own. The shape of them felt deliberate. Detection systems don't see that. People do.

@Jeff Hamm 3/9/2026
Built for defenders, backed by believers. Announcements

Built for defenders, backed by believers.

Huntbase has closed its first funding round, led by Osney Capital, the UK's only cyber-specialist seed fund, alongside angel investors through Halceon, who back early-stage companies working in cyber, national resilience, and defence. This isn't just a funding milestone. It's a signal that the mission to give security teams clearer, faster, smarter investigation capability is one worth backing.

Huntbase Team 7/22/2025
The Human Edge: Why Analysts Remain Irreplaceable in an AI-Driven SOC Product

The Human Edge: Why Analysts Remain Irreplaceable in an AI-Driven SOC

AI can triage alerts, reduce noise, and surface patterns at machine speed. What it cannot do is notice that the admin logging in at 2 AM just handed in their notice, or that a string of low-severity events across three systems adds up to something that just doesn't feel right. The most dangerous gaps in a SOC aren't the ones algorithms miss. They're the ones no one thought to look for. That's still a human job.

@Tyler Oliver 4/29/2025
From Physical Hunting to Cyber Hunting: Extending Your Hunting Arsenal Security

From Physical Hunting to Cyber Hunting: Extending Your Hunting Arsenal

Threat hunting started with spreadsheets, log files, and a lot of patience. Then came EDR, cloud SIEMs, and eventually XDR, which pulled data from across the enterprise into a single, unified view. But the cyber forest is infinite and attackers adapt faster than any static method can keep up with. XDR is a powerful step forward, and it may already be a stepping stone to something bigger: AI-driven detection that doesn't just correlate data, but anticipates what comes next.

@Tyler Oliver 4/15/2025
Ensuring Safe, Accessible AI Agents: Lessons Learned While Building Scout at Huntbase Product

Ensuring Safe, Accessible AI Agents: Lessons Learned While Building Scout at Huntbase

An AI agent with open access to your environment can investigate threats, quarantine systems, and block malicious traffic. It can also trigger an outage with a single ill-timed request. Building Scout at Huntbase meant confronting that tension directly: how do you give an AI agent enough freedom to be useful without risking serious damage if something goes wrong? The answer turned out to be hiding in plain sight, in the design principles that integration platforms and query-based interfaces have relied on for years.

@Tyler Oliver 4/15/2025
The AI SOC Is Here - But It’s Not What You Think Product

The AI SOC Is Here - But It’s Not What You Think

Nearly every security vendor is selling a vision of the autonomous SOC, a system that detects, triages, and resolves threats without human input. Gartner calls that vision unrealistic. The reality is quieter but more interesting: AI is being woven into security operations as a force multiplier, handling the repetitive work so analysts can focus where judgment actually matters. The AI SOC isn't a takeover. It's a team.

@Tyler Oliver 4/14/2025
Founder Spotlight: [Me] on Building Huntbase — Cyber Runway Company

Founder Spotlight: [Me] on Building Huntbase — Cyber Runway

Seven thousand alerts in the queue. Every day. And the team had just accepted it. That moment stayed with me long after the engagement ended, and it became the frustration that eventually became Huntbase. We're not building another dashboard for SOC managers or another automation layer that quietly replaces analysts. We're building for the person staring at the screen when the playbook ends and human judgment begins.

@Tyler Oliver 4/11/2025
Beyond the Bots: Reclaiming the Art of Investigation in the AI-Powered SOC Security

Beyond the Bots: Reclaiming the Art of Investigation in the AI-Powered SOC

AI-powered SOC tools promise to resolve alerts faster, reduce fatigue, and automate away the noise. But automating the routine doesn't solve cybersecurity's hardest problems, it shifts them. What remains after automation clears the easy cases are complex incidents hiding in ambiguity, subtle adversaries quietly persisting, and threats without signatures. The toughest work in security begins exactly where automation ends.

@Tyler Oliver 4/8/2025
From Chatbots to Trusted AI Agents: Graphs as the Backbone of AI Cybersecurity Use Cases Engineering

From Chatbots to Trusted AI Agents: Graphs as the Backbone of AI Cybersecurity Use Cases

Most AI security tools produce confident-sounding answers, but confidence isn't context. True threat intelligence requires understanding the relationships between users, systems, adversaries, and events. In this post, we explore why graph technology is the missing link that transforms AI from a chatbot into a reasoned security partner, and how combining knowledge graphs with real-time event graphs gives analysts and AI agents a genuinely 3D view of the threat landscape.

@Tyler Oliver 4/3/2025
Founder Spotlight: David Read, Ossprey — Cyber Runway Startups

Founder Spotlight: David Read, Ossprey — Cyber Runway

Every time a developer installs an open-source package, they're implicitly trusting that it's safe. But most security tools can't actually tell you if a package is malicious. David Read watched this problem play out in real time when UA-Parser-JS, a widely used library, was hijacked and downloaded over 100,000 times before anyone caught it. Frustrated by the lack of solutions, he built Ossprey to analyze open-source code at scale and catch hidden threats before they ever reach production.

@Tyler Oliver 3/17/2025
Founder Spotlight: Ahmed Shosha, Stealthium — Cyber Runway Startups

Founder Spotlight: Ahmed Shosha, Stealthium — Cyber Runway

Attackers don't operate in isolation. They spread laterally, interact with external services, and exploit entire application stacks. Yet most security testing environments still assess threats on a single machine, missing exactly how modern attacks unfold. Ahmed Shosha spent years building sandboxing solutions at Microsoft before founding Stealthium to close that gap, creating execution environments that replicate real-world conditions so security teams can finally see threats behave the way they actually do.

@Tyler Oliver 3/12/2025
The Integration Bottleneck in Cybersecurity: An Old Problem with New Urgency Product

The Integration Bottleneck in Cybersecurity: An Old Problem with New Urgency

Over 3,700 cybersecurity vendors. Dozens of tools in a typical enterprise SOC. And almost none of them naturally talk to each other. The integration bottleneck in security isn't a new problem, but the stakes have never been higher. When threat data gets stuck in one system and never reaches the SIEM, or an unintegrated sensor can't trigger an endpoint isolation in time, the gaps become real vulnerabilities. This post digs into why integration remains so hard, where traditional solutions fall short, and what's actually working.

Huntbase Team 3/12/2025
Founder Spotlight: Kieran Roberts, Fortifi Cyber — Cyber Runway Startups

Founder Spotlight: Kieran Roberts, Fortifi Cyber — Cyber Runway

Most companies get the same generic pentest year after year, a compliance checkbox that rarely reflects their actual risk. Kieran Roberts spent years watching this pattern play out at some of the biggest names in the industry before founding Fortifi Cyber to fix it. The goal isn't just to find vulnerabilities and write reports. It's to help businesses understand what actually matters and build security programs around real threats.

@Tyler Oliver 2/28/2025
Founder Spotlight: Tom Whelan, Co-Founder of eCora - Cyber Runway Startups

Founder Spotlight: Tom Whelan, Co-Founder of eCora - Cyber Runway

Tom Whelan took a year off to ride a motorbike across Africa, came back and built a travel startup, watched COVID kill it overnight, and then co-founded a company solving one of the hardest problems in application security. eCora puts applications in a secure execution environment so they stay protected even when the underlying infrastructure can't be trusted. As AI adoption accelerates and geopolitical risks reshape the threat landscape, that turns out to be exactly what the market needs.

@Tyler Oliver 2/25/2025
Founder Spotlight: Chris Eastwood & Alistair Kennedy, The Rybec Group — Cyber Runway Startups

Founder Spotlight: Chris Eastwood & Alistair Kennedy, The Rybec Group — Cyber Runway

Most cybersecurity founders come from technical or corporate backgrounds. Chris Eastwood and Alistair Kennedy came from the police. After years working cybercrime units across the UK, they retired early and noticed a gap no one was filling: businesses weren't being warned, schools weren't being educated, and the outreach that law enforcement once provided had quietly disappeared. So they built Rybec to fill it themselves.

@Tyler Oliver 2/20/2025