Open source

Your hunts should outlive your tools.

Huntbase is the open threat-hunting platform. The formats we hunt in are published, the hunts we write are public, and the standards we use are ones you can take anywhere.

01What we publish

Open work you can read, fork and keep.

Spec · MIT

hunt.md

An open, plain-text format for threat hunt playbooks: Markdown with YAML frontmatter, one heading per step, fenced blocks for queries. It reads fine with no tooling, diffs cleanly, and ties you to no vendor.

Read the spec on GitHub

More than 240 hunts

Huntbase Hub

Hunt playbooks built from current public research and reviewed by a person before they are published. Each one has a hypothesis, steps, a coverage map and named blind spots, as a hunt.md file. No account needed.

Browse the HubFork the hunts

02Open standards

Standards you can take anywhere.

OCSF v1.3

The schema Huntbase normalises results to, so one query or rule runs on every matching source.

Sigma

The language you write detection watchers in, including SigmaHQ community rules.

STIX 2.1 and TAXII 2.1

STIX patterns translated for each source, and your own private TAXII 2.1 feeds.

CACAO v2

Hunt playbooks exported in the OASIS standard for courses of action.

03Built on open source

Open at the endpoint, too.

Endpoint Control, in early access, is built on open-source osquery. It asks your hosts live questions mid-hunt, for the times the log was never collected.

Questions

Is Huntbase open source?

The Huntbase platform is not. What we publish in the open is the hunt.md specification (MIT), the hunts on the Huntbase Hub, and support for open standards such as OCSF, Sigma, STIX, TAXII and CACAO, so your work is never locked in.

What is hunt.md?

An open, plain-text format for threat hunt playbooks: Markdown with YAML frontmatter, one heading per step and fenced blocks for queries. The spec, examples and tooling are on GitHub under the MIT licence.

Can I use Huntbase Hub hunts without Huntbase?

Yes. Every hunt on the Hub is a hunt.md file you can read, download or fork without an account. Queries are written against a normalised schema, so you may need to adapt field names to your own sources.

Your data.
Your knowledge.
Your call.

Run any Hub hunt against your own data. Sign up and connect a source, or book a demo.

  1. 01Sign up
  2. 02Run a guided hunt on the sample workspace, no connector needed
  3. 03Connect your own sources when you're ready