Find the genuinely new. Then hunt back.
A known CVE sprayed a million times is noise. A familiar loader through an unseen endpoint is a lead. huntback scores the novelty of the entry vector, keeps exploitation evidence separate, and turns the firehose into a short queue of cases worth your time.
Novelty of the vector, not scariness of the payload
We score the entry vector: the path, parameters, technique and product context. A vector we already recognise (our signature, or a commodity in-the-wild exploit) is not novel, however dramatic its stage-2. Exploitation evidence is tracked on a separate ladder, so a passive sensor is never penalised.
- Entry-vector novelty vs the right cohort
- Evidence level kept separate from novelty
- Known malware family does not lower a novel entry
- A bounded case queue, not 100k logs
same loader via /api/v4/agent interest 70 novel
CVE-2024-4577 canned probe 14 known
Everything a threat hunter needs
Reconstruct the chain, score it, corroborate it, and act.
Novelty scoring
A transparent rubric across trigger, target, sequence, exploit plausibility and corroboration.
Attack-chain reconstruction
Requests, sessions and stage-2 stitched into one case, deduplicated by entry vector.
Counter-recon
One click scans the attacker's own infrastructure from a burner egress and harvests their tooling.
Live CVE intelligence
Which CVEs are being exploited on the network right now, with per-CVE permalinks.
Operator alerts
Get paged the moment a never-seen payload hits several sensors at once.
Case queue
A daily budget of the highest-signal cases plus outliers and a random audit sample.
More than a reputation feed
| Capability | huntback | Reputation / scanner feeds |
|---|---|---|
| Sees the full attack chain | yes | IP and port only |
| Scores what is genuinely new | yes | volume and reputation |
| Separates novelty from evidence | yes | no |
| Scans the attacker back | yes | no |
| Harvests attacker tooling | yes | no |
Hunting, answered
How is this different from a threat feed?
A feed tells you an IP is bad. huntback tells you how an attack was carried out, whether the technique is new, and lets you scan the attacker's infrastructure back.
What counts as novel?
A never-seen entry vector for the targeted product. A known exploit through an unfamiliar endpoint or parameter can still be novel, that is often the most valuable finding.
Stop drowning in noise
Get a bounded queue of the attacks that actually matter.