Advanced tool
Threat Hunting Query Builder.
Describe suspicious behavior. Enter builds KQL, Splunk SPL, Elastic/Lucene logic, required logs, confirmation evidence, and false positives.
Hunting scenarioEnter runs
Enter runs the tool. Shift plus Enter adds a new line. Maximum 100,000 characters.
Hunt packageKQL / SPL / Elastic
No hunt yet
Describe a scenario or load an example.