Skip to content

Latest commit

 

History

History
13 lines (8 loc) · 787 Bytes

hunt.rst

File metadata and controls

13 lines (8 loc) · 787 Bytes

Hunt

:ref:`soc` includes a Hunt interface which is similar to our :ref:`dashboards` interface but is tuned more for threat hunting.

images/56_hunt.png

The main difference between Hunt and :ref:`dashboards` is that Hunt's default queries are more focused than the overview queries in :ref:`dashboards`. A second difference is that most of the default :ref:`dashboards` queries display a separate table for each aggregated field, whereas many of the default queries in Hunt aggregate multiple fields in a single table which can be beneficial when hunting for more obscure activity.

Other than these two differences, Hunt and :ref:`dashboards` are very similar, so for more information please see the :ref:`dashboards` section.