Skip to main content
Hunt helps your team turn incoming threat intelligence into a durable workflow. Cotool ingests intel, decides whether it is relevant to your environment, checks for exposure or compromise signals, tracks coverage gaps, and creates alerts when something needs attention.

Main Hunt surfaces

Hunt has four main screens in the product:

Overview

A summary of recent intel, assessed threats, exposure alerts, rule proposals, and observability gaps.

Threats

The durable catalog of tracked threats, with grouped, table, and board views.

Intel Feed

The raw stream of ingested threat intelligence items.

Intel Sources

Where you manage built-in sources plus your own RSS, MISP, and TAXII feeds.

How Hunt works

At a high level, Hunt follows this flow:
1

Ingest intel

Cotool pulls threat intelligence from built-in sources, custom intel sources, or the /hunt-intel chat command.
2

Create or update a threat

Related intel is grouped into a durable threat record so the same threat can be tracked across assessments, alerts, and follow-up work.
3

Assess relevance and exposure

Cotool decides whether the threat applies to your environment and, when it does, runs an exposure assessment.
4

Capture outcomes

Hunt records findings such as compromise signals, exposure, no exposure, existing detection coverage, or telemetry gaps.
5

Open follow-up work

If Hunt finds something actionable, it creates a Hunt alert in Triage > Alerts. It can also propose new detection rules or track blocking observability gaps.

Understanding threat statuses

Threats move through derived statuses as Cotool learns more about them:
Active and Resolved follow the linked Hunt alert. For those threats, the source of truth is the alert workflow in Working Alerts.

Add and manage intel sources

Go to Hunt > Intel Sources to manage what Hunt ingests. You can add three custom source types:
  • RSS feed for vendor blogs, advisories, and newsletters
  • MISP server for private or public MISP-backed feeds
  • TAXII server for STIX 2.1 collections
The Intel Sources page shows:
  • Source health
  • Last sync time
  • Item volume over the last 24 hours
  • Whether the source is enabled
Built-in sources are managed by Cotool and appear automatically. For custom sources, you can enable or disable them, edit them, trigger a sync, or delete them when you no longer want their intel in Hunt.
TAXII and MISP sources can use public feeds or authenticated servers. If your server requires a token, provide it when you create the source.

Use the Intel Feed

The Intel Feed is where you review individual ingested intel items before or alongside threat-level analysis. Use it when you want to:
  • See which sources are producing new material
  • Open a specific advisory, post, or report
  • Trace a threat back to the underlying intel that produced it
The feed complements the Threats catalog:
  • Intel Feed = individual source items
  • Threats = durable, tracked threat records

Ingest a report from chat with /hunt-intel

If you already have a report URL, the fastest workflow is chat:
1

Start a chat command

In chat, type /hunt-intel.
2

Paste the report URL

Provide the URL of the advisory, blog post, or threat report you want Hunt to process.
3

Review the ingest result

Cotool runs the Hunt intel pipeline and streams progress in the chat timeline.
4

Continue from Hunt

From there, review the resulting intel item or threat record in the Hunt product area for follow-up.

Work a threat

Open Hunt > Threats to review the durable threat catalog. The Threats page supports:
  • Grouped view for status-based triage
  • Table view for scanning and sorting
  • Board view for a kanban-style workflow
  • Search by threat key, title, aliases, and actor
  • Filters for status, type, result, coverage, and actor
Open a threat to see its detail page. Depending on the threat, that page can include:
  • The latest assessment summary
  • Exposure and relevance indicators
  • Assets and evidence tied to the threat
  • Detection coverage
  • Proposed detection rules
  • Blocking telemetry gaps
  • A linked Hunt alert
  • A full activity timeline
If new intel arrives or your environment changes, use Reassess to rerun the Hunt workflow for that threat.

Alerts overview

See how Hunt findings turn into triage work items.

Working alerts

Investigate and close Hunt alerts when exposure needs action.