Get StartedGetting Started
Start Hunting
Execute high-speed searches across parsed artifacts to identify threats and pivot between data points. Hunting is performed against the Elasticsearch index generated during the Processing phase.
Accessing the Hunt Interface
- Select Case: From the Cases sidebar, open the target investigation case.
- Initialize Hunt: Click the Hunt button in the case page.

Analysis Views
The Hunt interface provides two primary modes for data interrogation:
Dashboard View (Visual Aggregation)
The default view provides a statistical overview of the case index via interactive widgets. Use this to identify outliers or volume spikes.

Table View (Raw Data Analysis)
Switch to Table View to perform granular line-item inspection. Click any row to expand the Record Detail panel for a full field-level breakdown.

Investigative Actions
- Pivot: Click values within the Record Detail panel to instantly apply them as new search filters.
- Export: Select Export to CSV to move filtered results into external analysis tools.
- Tagging: Bulk-select records to apply case-specific tags.
INFO
Hunting performance is optimized when specific filters are applied.

