huntback / hunt

Find the genuinely new. Then hunt back.

A known CVE sprayed a million times is noise. A familiar loader through an unseen endpoint is a lead. huntback scores the novelty of the entry vector, keeps exploitation evidence separate, and turns the firehose into a short queue of cases worth your time.

Start huntingBrowse CVE intelNo credit card required.
Discovery pipeline

Novelty of the vector, not scariness of the payload

We score the entry vector: the path, parameters, technique and product context. A vector we already recognise (our signature, or a commodity in-the-wild exploit) is not novel, however dramatic its stage-2. Exploitation evidence is tracked on a separate ladder, so a passive sensor is never penalised.

  • Entry-vector novelty vs the right cohort
  • Evidence level kept separate from novelty
  • Known malware family does not lower a novel entry
  • A bounded case queue, not 100k logs
Mozi loader via /shell? interest 8 known
same loader via /api/v4/agent interest 70 novel
CVE-2024-4577 canned probe 14 known
The toolkit

Everything a threat hunter needs

Reconstruct the chain, score it, corroborate it, and act.

🔬

Novelty scoring

A transparent rubric across trigger, target, sequence, exploit plausibility and corroboration.

🧩

Attack-chain reconstruction

Requests, sessions and stage-2 stitched into one case, deduplicated by entry vector.

🎯

Counter-recon

One click scans the attacker's own infrastructure from a burner egress and harvests their tooling.

â—Ž

Live CVE intelligence

Which CVEs are being exploited on the network right now, with per-CVE permalinks.

📨

Operator alerts

Get paged the moment a never-seen payload hits several sensors at once.

🗂

Case queue

A daily budget of the highest-signal cases plus outliers and a random audit sample.

Why huntback

More than a reputation feed

CapabilityhuntbackReputation / scanner feeds
Sees the full attack chainyesIP and port only
Scores what is genuinely newyesvolume and reputation
Separates novelty from evidenceyesno
Scans the attacker backyesno
Harvests attacker toolingyesno
FAQ

Hunting, answered

How is this different from a threat feed?

A feed tells you an IP is bad. huntback tells you how an attack was carried out, whether the technique is new, and lets you scan the attacker's infrastructure back.

What counts as novel?

A never-seen entry vector for the targeted product. A known exploit through an unfamiliar endpoint or parameter can still be novel, that is often the most valuable finding.

Stop drowning in noise

Get a bounded queue of the attacks that actually matter.