Threat HuntingNew
A structured threat hunting module with 7 preset hunts spanning network detections, endpoint anomalies, UBA signals, cloud security events, and AD misconfigurations — enabling analysts to proactively surface threats that evade automated detection.
Threat Hunting
Proactive threat hunting across your entire environment
Key capabilities
7 Preset Hunts
Pre-built hunt queries across HakObserver, FortiGate, Netskope, UBA, and Microsoft Defender — ready to run immediately without query authoring.
Multi-Source Coverage
Hunt hypotheses span network traffic anomalies, endpoint process anomalies, insider threat signals, cloud DLP events, and AD lateral movement paths.
Hunt Parameters
Each preset includes configurable parameters — time range, severity threshold, entity filters — for scoped, targeted investigation.
Investigation Integration
Hunt findings can be escalated directly into the Investigations module with evidence pre-attached and IOCs pre-populated.
Hunt Results Dashboard
Results are displayed in a structured panel with severity, entity, timestamp, and raw evidence — drill into any finding for full context.
Hunt Library
Analysts can save custom hunt parameters and results for repeat execution — building an institutional hunt library over time.
Why Threat Hunting?
- 7 prebuilt hunts across HakObserver, FortiGate, Netskope, UBA, and Defender
- No query language required — parameter-driven hunting
- Direct escalation from hunt findings to Investigations
- Covers network, endpoint, identity, and cloud hunt hypotheses
- Hunt library for repeatable, systematic threat hunting programmes
Threat Hunting is part of the Hakware OneView platform. All findings, events, and data from this module flow into your central dashboard alongside every other security signal in your environment.
See Threat Hunting in action
Request a personalised demo and we'll show you exactly how Threat Hunting works within your environment.