Huntbase is open
Anyone can now sign up for Huntbase, connect a source they already have, and run a reviewed hunt against their own environment. Free today, no card, and a plain account of what the agent does with your data.
TL;DR — Huntbase is open. Sign up at app.huntbase.io, connect a source you already have, and run any of the 149 reviewed hunts on the Hunt Hub against your own environment. No request form and no call first. It is free today, with no card. Below: what to expect, what our agent does with your data, and what isn't open yet.
→ Sign up
What changed today
Until now you had to ask us for access. From today you don't. On Tuesday we published the Hunt Hub: threat hunts built from current public research, each reviewed by a person. Today you can run them.
Two kinds of people have been asking for this, and they want different things from it.
If you are defending against something right now
You have read the write-up. You want to know whether it is in your environment, and you do not have half a day to build the hunt.
- Find the hunt on hub.huntbase.io. Read the hypothesis, the queries and the blind spots before you trust it. The most-run hunt this week is Correlating Proxy-Obscured Identity and Endpoint Activity, built from Red Canary research: it tests whether someone is signing in through Okta from multi-hop proxy infrastructure and then running discovery commands on an endpoint.
- Press Run hunt and sign up.
- Connect a source. Huntbase queries the tools you already run, where the data already lives. The integrations page lists what we connect to today, including Splunk, Microsoft Sentinel, CrowdStrike and Elastic.
- Run it. Each step shows the query, what came back and what it means for the hypothesis. You record the verdict.
If you are curious how agents fit into security work
You have heard that agents will change this job. You would like to see one do real work that you can check.
In Huntbase the hunt is the structure and the agent, Scout, works inside it. A hunt is a graph of steps: queries, analytics, checkpoints where a person decides whether to go on, and tasks. Scout can draft a hunt, propose the next query, and analyse what comes back. Every one of those is a step you can read, change or throw away.
Two defaults are worth knowing:
- In chat, Scout proposes queries and waits for you to run them.
- Automated hunts default to a supervised mode, where steps wait for an analyst's approval. An organisation can choose to change that.
We would rather you judged this by using it than by reading about it.
What you need
- A data source we connect to today.
- A few minutes to sign up, create your organisation and connect it.
- Nothing else. There is nothing to deploy in order to start.
What isn't open yet
Better to say it here than have you find a locked door. These are available by request from inside the app:
- Watchers, which run a hunt or playbook on a trigger as well as support your existing detection library
- Bring-your-own data lake
- Endpoint Control
Price
Huntbase is free to use today. There is no card and no trial clock.
Honest status
- This is early. Things will break. Tell us where.
- If you sign up without a source to connect, there is not much to do yet. We are working on a sample environment so you can try a hunt end to end without connecting anything.
- Scout gets things wrong. That is why every step is visible and the verdict is yours.
→ Sign up · Browse the hunts first