Detection & Response
Threat Hunting
Hypothesis-driven hunts across all your telemetry.
Available as a standalone module · Add to my package12Open incidents
41,208Events / sec
27Auto-contained
- Query across all sources at onceActive
- IOC and technique pivotsActive
- Saved huntsActive
- Promote a hunt to a detection ruleActive
What it does
Search historical events for techniques, indicators and behaviours that rules have not caught yet, and turn good hunts into new detections.
Query across all sources at once
IOC and technique pivots
Saved hunts
Promote a hunt to a detection rule
How it worksin three steps.
Collect
Events from agents, syslog and connectors are normalised into one schema.
Detect
SIGMA, YARA and IOC matches run in real time and are correlated into incidents.
Respond
Contain the threat from the console, with approval for high-impact actions.
Works best withthese modules.
See all 30 modules
Endpoint Security
Agents
Signed lightweight agents for Windows, Linux and macOS.
Learn more Threat IntelligenceThreat Intelligence Feeds
IOC feeds matched against every event.
Learn more Automation & AISOC Automation
Visual flows from detection to response.
Learn moreAlso in Detection & Response
Ready to see it on your own data?
A 30-minute walkthrough with an engineer, tailored to your environment.