Open source
01What we publish
Spec · MIT
An open, plain-text format for threat hunt playbooks: Markdown with YAML frontmatter, one heading per step, fenced blocks for queries. It reads fine with no tooling, diffs cleanly, and ties you to no vendor.
More than 240 hunts
Hunt playbooks built from current public research and reviewed by a person before they are published. Each one has a hypothesis, steps, a coverage map and named blind spots, as a hunt.md file. No account needed.
02Open standards
The schema Huntbase normalises results to, so one query or rule runs on every matching source.
The language you write detection watchers in, including SigmaHQ community rules.
STIX patterns translated for each source, and your own private TAXII 2.1 feeds.
Hunt playbooks exported in the OASIS standard for courses of action.
03Built on open source
Endpoint Control, in early access, is built on open-source osquery. It asks your hosts live questions mid-hunt, for the times the log was never collected.
The Huntbase platform is not. What we publish in the open is the hunt.md specification (MIT), the hunts on the Huntbase Hub, and support for open standards such as OCSF, Sigma, STIX, TAXII and CACAO, so your work is never locked in.
An open, plain-text format for threat hunt playbooks: Markdown with YAML frontmatter, one heading per step and fenced blocks for queries. The spec, examples and tooling are on GitHub under the MIT licence.
Yes. Every hunt on the Hub is a hunt.md file you can read, download or fork without an account. Queries are written against a normalised schema, so you may need to adapt field names to your own sources.
Run any Hub hunt against your own data. Sign up and connect a source, or book a demo.