Hunt Plan Builder
Build a complete, structured hunt plan from a hypothesis with data sources, indicators, and escalation path.
Build hunt plan →Hunt Hypothesis Library
Structured hunt hypotheses organised by MITRE tactic with rationale, log sources, and ready queries.
Browse hypotheses →Sigma Rule Converter
Paste any Sigma rule and convert to SPL, KQL, or EQL instantly. Runs client-side.
Convert rule →SPL Hunt Query Library
Production-ready Splunk SPL hunt queries organised by MITRE technique with tuning guidance.
Browse SPL queries →KQL Hunt Query Library
Microsoft Sentinel and Defender KQL queries for Windows, Azure AD, and O365.
Browse KQL queries →IOC to Hunt Query Converter
Paste IOCs from any threat report. Get SPL and KQL queries searching all event types.
Convert IOCs →Beacon Detection Calculator
Understand C2 beacon timing patterns and get SPL/KQL queries for beaconing detection.
Hunt beacons →Long Tail Frequency Analyser
Find rare process executions or DNS queries appearing on only 1-2 hosts.
Analyse frequency →LOLBin Cluster Hunt
Clusters of 3+ LOLBins from same process in 15 minutes are near-uniquely malicious.
Hunt clusters →Kerberos Attack Hunt Suite
Complete hunt suite for Kerberoasting, AS-REP Roasting, Pass-the-Ticket, Golden/Silver Ticket.
Hunt Kerberos attacks →SMB Lateral Movement Hunt
Distinguish malicious SMB lateral movement from legitimate file sharing.
Hunt SMB movement →Lateral Movement Hunt Pack
WMI, DCOM, WinRM, RDP, token impersonation — every lateral movement technique.
View hunt pack →Insider Threat Hunt Pack
Off-hours activity, abnormal data access, bulk downloads, email forwarding rules.
View hunt pack →Data Staging & Exfil Hunt
Hunt for pre-exfiltration staging — large file copies, ZIP creation, cloud uploads.
Hunt data staging →Ransomware Pre-Encryption Hunt
Catch ransomware before encryption — shadow copy enumeration, credential dumping.
Hunt ransomware staging →