Back to Blog
Product

Hunting Doesn't Stop at Live Data: Introducing Federated Data-at-Rest Search

@huntbase July 28, 2026 ~3 mins

Huntbase now searches data at rest. Bring your own acquired data — log exports, evidence collections, telemetry that never made it into your SIEM — and hunt across it alongside live systems and cloud sources like AWS, all in one federated query, all driven by Scout's intelligence-led guidance. Live and historical, one hunt.

London, July 29, 2026 — Huntbase has added data-at-rest search to its agentic threat hunting and triage platform. Security teams can now hunt across previously acquired data, such as exported logs, archived telemetry, and evidence collections, in the same federated workflow they already use for live sources.

Huntbase powers Scout, the company's guidance product, which uses intelligence to drive the hunting process forward. Since launch, the platform has worked by querying live sources directly at the moment a hunt needs them: SIEMs, applications, endpoints, cloud platforms, each reached through its own formal integration. There is no ingestion pipeline to build and no second copy of your data to store and pay for. You ask the question where the data already lives. That has been the design from the start, not a later addition.

This release extends the same approach to data that has no query layer in front of it at all. A SIEM or a cloud platform can answer a query through its native interface. A server full of acquired forensic evidence, or years of telemetry exports sitting in cheap storage, cannot. Huntbase can now hunt across that raw data too. Load it and go to work.

Why it matters

Responders often work from acquired data rather than live access. Compromise assessments in particular tend to start with a pile of collected evidence and no agent on anything. Huntbase now handles these engagements natively, with the same rigor as a live investigation.

Most security teams also hold far more telemetry than their SIEM has ever seen, usually because ingesting it would cost too much. That data stopped being useful the day it landed in cold storage. It is now searchable hunting ground, without re-ingesting any of it.

And because a single query spans both live and historical data, you no longer choose between what is happening now and what happened before. Scout applies the same intelligence-driven guidance to both.

What this looks like in practice

Huntbase queries live endpoints via osquery, reaches cloud systems and storage such as AWS, and now searches data at rest, all within one federated query. Some of the workflows this opens up:

Incident response with historical context. During an active intrusion, an operator queries live endpoints for a suspicious persistence mechanism while sweeping acquired forensic images and archived logs for the same indicator. One pass tells the team where the attacker is and how long they have been there.

Compromise assessment across evidence and cloud. A team assessing a client environment loads a server of acquired logs and telemetry exports, then federates that search with the client's live AWS environment: CloudTrail activity, S3-stored state data, running workloads. The question being answered is whether historical footholds are still active today.

Retro-hunting new intelligence. When fresh threat intel lands, Scout runs one hunt that checks live systems for current presence and replays the same indicators against months of telemetry outside the SIEM. Threats that predate your detection rules stop slipping through.

Cloud-scale telemetry hunting. Teams that offload high-volume telemetry to cloud storage for cost reasons can hunt across it directly and correlate findings with live endpoint state in the same query. Nothing gets re-ingested into a SIEM first.

Action and collection. Hunting does not stop at search. When a hit surfaces, operators can pull artifacts from a live endpoint, grab objects from cloud storage, or expand the at-rest dataset, all from the same workflow.

See it on your data

Data-at-rest search is available now to all Huntbase customers. If you're not one yet, the fastest way to understand it is to bring a real dataset: an old evidence server, a bucket of telemetry exports, whatever you have sitting in storage.

#Security #Platform Update
More Articles