Hunting and detection
Hunts that open in your console.
Detection content arrives mapped to the technique it covers and written in your platform's own query language, using your index and your field names, with a link straight into your console. Not a snippet somebody has to translate before it runs.
- 01
Ten platforms, native output
Queries generated for Elastic, Splunk, Sentinel, QRadar, Chronicle, CrowdStrike, Defender, SentinelOne, Carbon Black and Cortex XDR, each in that platform's own language.
- 02
Mapped to technique, not to a blog post
Every piece of detection content is tied to the adversary technique it covers, so coverage is a question you can answer rather than a feeling.
- 03
Coverage you can see and track
Which techniques you detect, which you do not, and which matter most for the threats currently pointed at your sector.
- 04
A hunt has a lifecycle
Hypotheses, ownership, comments and outcomes, so a hunt that found nothing is recorded as having been run rather than quietly forgotten.
- Elasticsearch / Kibana
- KQL
- Splunk
- SPL
- Microsoft Sentinel
- Sentinel KQL
- IBM QRadar
- AQL
- Google Chronicle / SecOps
- YARA-L
- CrowdStrike Falcon
- FQL
- Microsoft Defender for Endpoint
- MDE KQL
- SentinelOne
- S1QL
- VMware Carbon Black
- CB Query
- Palo Alto Cortex XDR
- XQL
What we commit to
Things that stay true, or they are defects.
Your fields, not ours
Field mappings and index names are held per platform per customer, so a query runs as written.
Exportable
Indicator lists, structured intelligence and detection content leave in open formats.
Nothing runs itself
The platform generates and links. It does not execute anything against your estate on its own.
See it against your own estate.
The useful version of this conversation uses your data, not ours. Bring a vulnerability, a supplier or a domain you already care about.