Pillar 04 of 12

Hunt across the estate.
Land on the raw line.

Hunting fails when the pivot breaks. Every number on every hunting view resolves to the findings that produced it, and every finding resolves to the decoded event and the original line. There is no dead end.

nullsoc.in / threat-hunting
The NullSOC threat hunting view: KPI band, severity breakdown, a stacked stream of detections over time and ranked rules.

The hunting overview. Every tile narrows with the agent and time controls in the header.

5
Hunting views
Overview, authentication, endpoint, ATT&CK and events.
14
Tactics
The full ATT&CK enterprise matrix, lit by your own rules.
1
Click to raw
Any technique or rule resolves to the events behind it.
3.8M
Geo records
City level GeoIP, resolved at decode and refreshed automatically.
The surface

One place to look, organized the way you hunt.

Authentication, endpoint, network and technique coverage each get their own view, sharing one agent selector and one time window. Change the scope once and every view narrows with it, so a hunt does not restart when you change tab.

  • Overview is the shape of the day: severity, volume over time, top rules, top sources.
  • Authentication is failures against successes, by geography, account and host.
  • Endpoint is process, file, registry and configuration activity per agent.
  • Events is the full Discover surface, already scoped to what you were looking at.
nullsoc.in / threat-hunting
The hunting view showing a stacked stream of detections by severity with ranked rules and agents.

Detections stacked by severity, with ranked rules and the agents behind them.

ATT&CK

A matrix lit by your detections, not a poster.

Technique identifiers are carried on the rules themselves, so coverage is computed from what actually fired in your estate rather than from a claim about what the product could detect. An empty cell is an honest gap you can go and close.

  • Techniques and tactics come from the rule metadata, imported with the ruleset and editable in YAML.
  • Volume per technique shows what is loud, and what fired exactly once and deserves a look.
  • Per agent breakdown answers which host carried a technique, not just whether it appeared.
  • Straight to evidence. A technique resolves to its findings, and a finding to the event that caused it.
nullsoc.in / mitre
The NullSOC MITRE ATT&CK view with technique counts and tactic coverage from live detections.

Coverage computed from rules that actually fired, not a capability claim.

Geography

Where it came from, resolved at decode.

Every routable address is resolved to country, coordinates and autonomous system as the event is decoded, using a full GeoLite2 City database rather than a country only lookup. Geography is therefore a field you can filter, chart and correlate on.

  • Country, coordinates and ASN are attached before a rule ever sees the event.
  • Correlate on it. Impossible travel is a correlation over source.geo.country_iso_code, not a separate product.
  • Attack origin map ranks source countries and the networks behind them by volume.
  • Enrichment is configuration. Which fields get geo resolved is an editable field group, not compiled behaviour.
nullsoc.in / overview
The attack origins map: source countries plotted with volume sized markers and arcs into the estate.

Attack origins, sized by volume. The same field is filterable in Discover.

The pivot

Every number is a question you can open.

A hunting view that cannot show its working is a dashboard, not a tool. Each aggregate resolves down through the layers to the exact line on the wire, with the identifier that links them printed on the finding.

  • Aggregate to findings. A ranked row opens the findings that make up its count.
  • Finding to event. Every finding carries the decoded document that triggered it.
  • Event to raw. The original untouched line is kept and reachable by trace identifier.
  • Then to a case. Promote what you found, and the observables come across already extracted.
Hunting facts
Scope controlsagent selector and time window, shared
Time contractone window definition across the platform
ATT&CK sourcetechnique ids carried on the rules
Geo sourceGeoLite2 City, country, coordinates, ASN
Pivot depthaggregate to finding to event to raw line
Promoteto an alert or a case, observables extracted
ExportCSV from any table, PDF or Excel report
Get started

Bring a technique you assume
you are covered for.

Name an ATT&CK technique your current tool claims. We will show you whether a rule in your estate has ever actually fired on it.

Powered by Codesecure Solutions. Self hosted, cloud or fully managed.