Hunt across the estate.
Land on the raw line.
Hunting fails when the pivot breaks. Every number on every hunting view resolves to the findings that produced it, and every finding resolves to the decoded event and the original line. There is no dead end.
The hunting overview. Every tile narrows with the agent and time controls in the header.
One place to look, organized the way you hunt.
Authentication, endpoint, network and technique coverage each get their own view, sharing one agent selector and one time window. Change the scope once and every view narrows with it, so a hunt does not restart when you change tab.
- ▸Overview is the shape of the day: severity, volume over time, top rules, top sources.
- ▸Authentication is failures against successes, by geography, account and host.
- ▸Endpoint is process, file, registry and configuration activity per agent.
- ▸Events is the full Discover surface, already scoped to what you were looking at.
Detections stacked by severity, with ranked rules and the agents behind them.
A matrix lit by your detections, not a poster.
Technique identifiers are carried on the rules themselves, so coverage is computed from what actually fired in your estate rather than from a claim about what the product could detect. An empty cell is an honest gap you can go and close.
- ▸Techniques and tactics come from the rule metadata, imported with the ruleset and editable in YAML.
- ▸Volume per technique shows what is loud, and what fired exactly once and deserves a look.
- ▸Per agent breakdown answers which host carried a technique, not just whether it appeared.
- ▸Straight to evidence. A technique resolves to its findings, and a finding to the event that caused it.
Coverage computed from rules that actually fired, not a capability claim.
Where it came from, resolved at decode.
Every routable address is resolved to country, coordinates and autonomous system as the event is decoded, using a full GeoLite2 City database rather than a country only lookup. Geography is therefore a field you can filter, chart and correlate on.
- ▸Country, coordinates and ASN are attached before a rule ever sees the event.
- ▸Correlate on it. Impossible travel is a correlation over
source.geo.country_iso_code, not a separate product. - ▸Attack origin map ranks source countries and the networks behind them by volume.
- ▸Enrichment is configuration. Which fields get geo resolved is an editable field group, not compiled behaviour.
Attack origins, sized by volume. The same field is filterable in Discover.
Every number is a question you can open.
A hunting view that cannot show its working is a dashboard, not a tool. Each aggregate resolves down through the layers to the exact line on the wire, with the identifier that links them printed on the finding.
- ▸Aggregate to findings. A ranked row opens the findings that make up its count.
- ▸Finding to event. Every finding carries the decoded document that triggered it.
- ▸Event to raw. The original untouched line is kept and reachable by trace identifier.
- ▸Then to a case. Promote what you found, and the observables come across already extracted.
Bring a technique you assume
you are covered for.
Name an ATT&CK technique your current tool claims. We will show you whether a rule in your estate has ever actually fired on it.
Powered by Codesecure Solutions. Self hosted, cloud or fully managed.