CISO dinner in Vancouver, Sept 9RSVP
Alaris
Pricing

Find adversaries before they find a foothold.

Organize hypotheses into campaigns, test them manually or with agents, and turn the evidence into defensible conclusions.

Campaigns, Hunts & Findings

Every hunt belongs to a bigger story

Campaigns group related hunts around an intrusion, threat actor, or mission. Each hunt tests one hypothesis, gathers its findings, and preserves a clear conclusion, so a multi-hunt effort reads as one connected investigation.

Search hypothesis, ID, technique…OpenClosedAll
Hunts 16Run all drafts (16)+ New hunt
HNT-2033If ransomware was staged, commands disabling Defender and deleting VSS copies will have executedDraft
ManualImpair DefensesInhibit RecoveryNo findings yet
HNT-2031If network discovery occurred, netscan.exe will have run from a non-standard directoryDraft
ManualNetwork DiscoveryNo findings yet
HNT-2030If NetExec enabled lateral movement, SMB targets and credential lists will be presentDraft
ManualSMB / Admin SharesPassword SprayingNo findings yet
HNT-2029If remote services were deployed, GoToResolve will appear across multiple systemsDraft
ManualSoftware DeploymentRemote ServicesNo findings yet
HNT-2028If directory credentials were dumped, NetExec will target domain controllersDraft
ManualNTDSNo findings yet
Hypothesis-Driven Hunts

One hypothesis. Two ways to test it

Every hunt starts with a hypothesis, written by an analyst or generated from threat intelligence. Test it with an autonomous agent run or a manual query, then run it once or schedule it against fresh data.

New HuntDescribeImport
Hypothesis & Execution
Hypothesis Analyst-authoredA service account is authenticating from an origin it has never used before.Import threat intel
Execution Method
Findings require analyst reviewConfirm, dismiss, or escalate the hunt conclusion.5 sources
‹ Back Launch Hunt
Findings to Conclusion

Turn scattered evidence into one defensible verdict

Each meaningful observation becomes a finding tied to its entities. Shared hosts, users, and IPs connect those single-source findings into the hunt's multi-source conclusion, ready for an analyst to confirm, dismiss, or escalate.

Finish Hunt×
Hypothesis
Credential reuse connects identity and endpoint activity.
Findings disposition
3
Confirmed
0
Cleared
0
Pending
Techniques found
Valid AccountsRemote ServicesAccount Discovery
Findings (3)
Cross-source credential activity confirmed.
Escalate to alert
Promote confirmed findings.
Close as confirmed
Record the final conclusion.
Closure reason
Confirmed threat
Verdict
Threat found
Detection outcome
Detected by existing rule
Conclusion
The same service account links the identity, endpoint, and privilege findings.
CancelClose Hunt
MITRE Coverage & Recurring Hunts

See what you have hunted, and what comes next

Every hunt maps to MITRE ATT&CK, revealing the behaviors you have actively looked for and the gaps that remain. Schedule recurring hunts against priority techniques so the same question is tested against fresh data over time.

Tactics: 12 / 14Techniques: 38 / 852Hunts: 25 3+ hunts Recurring
Reconnaissance
7
T1589 Victim Info
T1590 Networks
T1591 Organization
T1593 Open Sites
T1594 Victim Sites
T1595 Active Scan
T1596 Open Data
Resource Dev.
6
T1583 Infrastructure
T1584 Compromise
T1585 Accounts
T1586 Accounts
T1587 Capabilities
T1588 Capabilities
Initial Access
7
T1078 Valid Accounts
T1091 Replication
T1133 External Service
T1189 Drive-by
T1190 Exploit Public
T1195 Supply Chain
T1566 Phishing
Execution
8
T1047 WMI
T1053 Scheduled Task
T1059 Command Shell
T1072 Software Deploy
T1106 Native API
T1129 Shared Modules
T1204 User Execution
T1569 System Services
Persistence
9
T1037 Logon Script
T1053 Scheduled Task
T1078 Valid Accounts
T1098 Account Manip.
T1133 External Service
T1136 Create Account
T1176 Browser Ext.
T1197 BITS Jobs
T1543 Create Service
Privilege Esc.
9
T1037 Logon Script
T1053 Scheduled Task
T1055 Process Inject
T1068 Exploitation
T1078 Valid Accounts
T1098 Account Manip.
T1134 Access Token
T1484 Domain Policy
T1547 Boot Logon
Defense Evasion
12
T1006 Direct Volume
T1014 Rootkit
T1027 Obfuscated
T1036 Masquerading
T1055 Process Inject
T1070 Clear Events
T1078 Valid Accounts
T1112 Modify Registry
T1127 Trusted Dev.
T1134 Access Token
T1140 Deobfuscate
T1197 BITS Jobs
Credential Access
9
T1003 OS Credential
T1040 Network Sniff
T1056 Input Capture
T1110 Brute Force
T1111 MFA Intercept
T1187 Forced Auth
T1212 Exploitation
T1528 Steal Token
T1539 Web Session
Discovery
9
T1007 System Service
T1010 App Window
T1012 Query Registry
T1016 Network Config
T1018 Remote System
T1033 System Owner
T1046 Network Scan
T1049 System Network
T1057 Process Discovery
Lateral Movement
8
T1021 Remote Service
T1072 Software Deploy
T1080 Taint Content
T1091 Replication
T1210 Exploitation
T1534 Internal Phish
T1550 Alternate Auth
T1563 Remote Service
Collection
9
T1005 Local Data
T1025 Removable
T1039 Network Share
T1056 Input Capture
T1074 Data Staged
T1113 Screen Capture
T1114 Email
T1115 Clipboard
T1119 Automated
Command & Control
8
T1071 App Protocol
T1090 Proxy
T1092 Comm Device
T1102 Web Service
T1104 Multi-Stage
T1105 Ingress Tool
T1132 Data Encoding
T1219 Remote Access

Find attackers who haven't triggered an alert yet