Discovery

Findings, potential detections and triage

A run produces findings. Findings are not detections until you say so. This page explains how to review findings, promote the real ones and dismiss the rest.

Findings and detections

Stage What it is Where you see it
Finding A result a check reported Run report, Findings tab
Potential detection A finding waiting for a decision Potential Detections page
Detection A finding you accepted. You can assign it, track it to closure and report on it. All Detections

Hunto does not add discovery findings to your detections on its own. You choose, either from the run report or from the Potential Detections queue. Findings you import from a file are the exception and are added automatically. See Import findings.

Add findings from the run report

  1. Open the run and go to the Findings tab.
  2. Tick the results to add, or open one and select Add to detections.
  3. Select Add N to detections and confirm.

Hunto tells you that this does not change the run's rating and sends no email for each finding. The result message says how many were added, how many matched a detection that already existed, how many were already in detections, and how many could not be added. Select Open detections to see them.

You can add up to 500 results at a time. Only runs from your own workspace can be added.

Review the Potential Detections queue

Open Potential Detections from the Investigate section. The page says: "Findings discovered by flows, awaiting a decision. Accept one to create a detection, or dismiss it as not real or out of scope."

Tabs

Tab Contains
Open Findings awaiting a decision
Accepted Findings you turned into detections
Dismissed Findings you rejected, with the outcome
Duplicate Findings that repeat a known detection

Each tab shows a count. The tab is kept in the page address.

The queue has one row per unique finding, not one per sighting. If a finding was seen five times, you decide once and the decision closes all five.

Columns and filters

Columns include Finding, Category, Asset, Type, Attributes, Score, Risk (Critical, High, Medium, Low, Info or unrated), In detections, Repeats and Change.

Filter Options
Search findings Title or value
Risk Critical to Info
Scored All findings, Scored only, Unrated only
Group Worst first, By asset, By category, By flow
Change For example Anything new, New findings, Back again, Raised in priority, New evidence, New source

Make a decision

Select a finding to open its detail pane, then choose:

Button Meaning
Accept Create a detection. If one already exists the finding is marked as a duplicate.
Not real The finding is wrong or not ours. Recorded as a false positive.
Out of scope Real, but you will not act on it.

When you dismiss, Hunto asks "Why are you dismissing this?" with four reasons:

Reason Meaning
Not our asset Real, but it does not belong to this organisation
Real, but accepted Correct, you know about it and you are not acting on it
The script is wrong The finding itself is incorrect
Already handled Tracked elsewhere, such as a ticket or another finding

Reasons help Hunto tune its checks, so choose the closest one.

For many at once, switch on bulk mode, tick the rows and use Accept, Not real or Out of scope in the bar. Keyboard shortcuts: a accepts, f marks not real, n marks out of scope, and J and K move between findings.

The detail pane

The pane shows the finding, its risk band and score, who it belongs to (ownership) and why, whether it is already in detections, and how many independent sources saw it (Corroboration). It also shows the evidence, attributes, triggered rules, the asset, the source, references and a diagnostics view of how the check found it.

If your workspace uses agent proposals, the pane may also show a suggested action with its evidence, doubts and next check. You can Accept, Override (with a reason) or Refuse it. A suggestion never acts on its own.

How accepted findings are scored

Detections you accept are scored on a 0 to 100 scale and banded:

Band Score
Critical 80 and above
High 60 to 79
Medium 35 to 59
Low 15 to 34
Info below 15

Some categories are capped: hygiene findings cap at Low, posture findings at Medium and inventory findings at Info. Exposure and leak findings are not capped.

Note: Accepting or dismissing a finding does not change the rating of the run it came from. The rating is computed from the run. How detections affect your wider security score is described in the scoring articles.

Use cases and wiring tips

  • Findings to tasks. Accept a finding, open the detection, go to its Tasks tab and select New task. The detection is linked to the task, which then follows your normal task queue.
  • Weekly sweep. After each weekly run, filter Potential Detections by Anything new and work the queue from Worst first.
  • Reduce noise. Use Out of scope for accepted risks, and Not real for wrong findings. Repeats of the same finding are then closed together.
  • Wiring. Accepted findings appear in All Detections, can raise incidents, feed notifications and reports, and count in your security score.