Hunt with method. Leave a detection behind.
Hunting without method produces anecdotes. Cyber Toolbox turns hunting into a repeatable discipline that grows your detection coverage and feeds your exposure and incident work — measured against the ATT&CK matrix.
Threat hunting is included in Pro — one tier, everything bundled
From a testable hypothesis to a durable detection.
H1
Build an ABLE hypothesis
Frame a testable hypothesis — Actor, Behaviour, Location, Evidence — tag it to MITRE ATT&CK, and score it so you hunt the right thing first.
H2
Run the searches
Work the query workbench against your log platform, capture matches, and build the picture without leaving the hunt.
H3
Keep facts from judgements
A determination of what happened never gets blurred with an assessment of who or why. Judgements carry a confidence level; facts stand on their own.
H4
Leave a detection behind
The payoff is a peer-reviewed threat summary and a durable detection candidate, so the same threat can’t walk in unseen twice.
H5
Escalate when it’s live
If a hunt turns up an on-sight compromise, it escalates straight into incident response — no re-keying, full lineage preserved.
Hunting that grows your coverage, not just your notes.
ABLE hypotheses (Actor, Behaviour, Location, Evidence), scored and queued.
MITRE ATT&CK coverage model + navigator — see your coverage across techniques and sub-techniques.
Query workbench to run searches against your SIEM and capture matches.
Facts-vs-judgements record — determinations and assessments never blurred.
Pyramid of Pain framing to hunt the indicators that actually cost an adversary.
Detections — promote a proven finding into a durable, shareable detection.
Escalate-to-IR for on-sight compromise, with lineage preserved.