Hunt Signals is a service that utilizes ThreatFilter by gathering threat intelligence data through a global sensor network, analyzing network scanning and cyberattacks to create detailed host profiles that include activity, classification, and geographical information.
Signals can be accessed by visiting https://app.hunt.io/signals, or by logging into the Hunt dashboard, then selecting Global Sensors.
You can query signals by entering your query in the search bar, then clicking Search.
For a little guidance, if you are looking to:
•
Search By IP
•
Examine all activity the host was involved in.
•
Type "ip:xxx.xxx.xxx.xxx", replacing "xxx.xxx.xxx.xxx" with the IP you wish to query.
•
Search By Actor
•
Explore all hosts related to an actor.
•
Type "actor:Name", replacing "Name" with the name of the actor you wish to query.
•
Search By Classification
•
Find hosts involved in malicious activity.
•
Type "classification:Name", replacing "Name" with the name of the classification you wish to query.
To view a list of actors, select Actors list →, or visit https://app.hunt.io/signals-actors.
This page provides information about all actors detected by Signals filter that hosts belong to.
Click on the actor on this page for more details.
For a little more guidance on seaching signals, select Search Types →, or visit https://app.hunt.io/signals-search-types.
Click on the actor on this page for more details.
This section displays the 10 most recently observed hosts from ThreatFilter.
This list will contain the IP, Geo, Organization, Actor ID, Classification, Tags, Ports, and Last seen indicators of the hosts.
Click on the actor on this page for more details.
This section details the activity of the last 24 hours with breakout charts for Countries, Organizations, Actors, and Tags.
Click on the actor on this page for more details.





