Main Hunt surfaces
Hunt has four main screens in the product:Overview
A summary of recent intel, assessed threats, exposure alerts, rule
proposals, and observability gaps.
Threats
The durable catalog of tracked threats, with grouped, table, and board
views.
Intel Feed
The raw stream of ingested threat intelligence items.
Intel Sources
Where you manage built-in sources plus your own RSS, MISP, and TAXII
feeds.
How Hunt works
At a high level, Hunt follows this flow:1
Ingest intel
Cotool pulls threat intelligence from built-in sources, custom intel
sources, or the
/hunt-intel chat command.2
Create or update a threat
Related intel is grouped into a durable threat record so the same threat
can be tracked across assessments, alerts, and follow-up work.
3
Assess relevance and exposure
Cotool decides whether the threat applies to your environment and, when
it does, runs an exposure assessment.
4
Capture outcomes
Hunt records findings such as compromise signals, exposure, no exposure,
existing detection coverage, or telemetry gaps.
5
Open follow-up work
If Hunt finds something actionable, it creates a Hunt alert in
Triage > Alerts. It can also propose
new detection rules or track blocking observability gaps.
Understanding threat statuses
Threats move through derived statuses as Cotool learns more about them:Active and Resolved follow the linked Hunt alert. For those threats,
the source of truth is the alert workflow in
Working Alerts.
Add and manage intel sources
Go to Hunt > Intel Sources to manage what Hunt ingests. You can add three custom source types:- RSS feed for vendor blogs, advisories, and newsletters
- MISP server for private or public MISP-backed feeds
- TAXII server for STIX 2.1 collections
- Source health
- Last sync time
- Item volume over the last 24 hours
- Whether the source is enabled
TAXII and MISP sources can use public feeds or authenticated servers. If
your server requires a token, provide it when you create the source.
Use the Intel Feed
The Intel Feed is where you review individual ingested intel items before or alongside threat-level analysis. Use it when you want to:- See which sources are producing new material
- Open a specific advisory, post, or report
- Trace a threat back to the underlying intel that produced it
- Intel Feed = individual source items
- Threats = durable, tracked threat records
Ingest a report from chat with /hunt-intel
If you already have a report URL, the fastest workflow is chat:
1
Start a chat command
In chat, type
/hunt-intel.2
Paste the report URL
Provide the URL of the advisory, blog post, or threat report you want
Hunt to process.
3
Review the ingest result
Cotool runs the Hunt intel pipeline and streams progress in the chat
timeline.
4
Continue from Hunt
From there, review the resulting intel item or threat record in the Hunt
product area for follow-up.
Work a threat
Open Hunt > Threats to review the durable threat catalog. The Threats page supports:- Grouped view for status-based triage
- Table view for scanning and sorting
- Board view for a kanban-style workflow
- Search by threat key, title, aliases, and actor
- Filters for status, type, result, coverage, and actor
- The latest assessment summary
- Exposure and relevance indicators
- Assets and evidence tied to the threat
- Detection coverage
- Proposed detection rules
- Blocking telemetry gaps
- A linked Hunt alert
- A full activity timeline
Related pages
Alerts overview
See how Hunt findings turn into triage work items.
Working alerts
Investigate and close Hunt alerts when exposure needs action.