Advanced tool

Threat Hunting Query Builder.

Describe suspicious behavior. Enter builds KQL, Splunk SPL, Elastic/Lucene logic, required logs, confirmation evidence, and false positives.

Hunting scenarioEnter runs

Enter runs the tool. Shift plus Enter adds a new line. Maximum 100,000 characters.

Hunt packageKQL / SPL / Elastic

No hunt yet

Describe a scenario or load an example.