Discovery

Import findings

Use Import findings to bring findings from another tool, a manual review or a vendor report into Hunto. Imported findings are recorded as a discovery and added straight to your detections, so they are scored, de-duplicated and tracked like any other.

Open the import pane

  1. Go to Discoveries.
  2. Open the menu in the page header and select Import findings.
  3. The pane Import discovery findings opens with two tabs: Upload a file and Add one.

Upload a file

  1. Select Upload a file and choose a .csv, .xls or .xlsx file.
  2. Review the preview. Hunto shows which rows are accepted and which are refused, with the reason.
  3. Commit the import.

A file can hold up to 5,000 rows.

Columns

Column Required Notes
Classification Yes The kind of finding. Must be a class Hunto recognises. The names type and category are also accepted as the header.
Value Yes The thing found, for example a domain or URL. At least 3 characters.
Target Yes The asset the finding is about.
Title No A readable title.
Severity No Info, Low, Medium, High or Critical.
Discovered At No When it was found.
Platform No Where it was found.
Host No The host involved.
Source No Where the finding came from.
Description No Free text.

Add one finding

Select Add one, fill in the same fields and commit. Use this for a single item from a report.

Rules Hunto applies

  • The Target must be one of your organisation's own domains. If your organisation has no domains recorded yet, this check is skipped.
  • A phishing, scam, advertisement or rogue application finding on your own domain is refused. It cannot be an impersonation of you if it is your domain.
  • Rows that repeat inside the file are merged into one.
  • Rows whose classification is not recognised are refused with a reason.

What happens when you commit

  1. Hunto creates one discovery record for the import. It has no schedule.
  2. Each accepted row is recorded as a finding, marked as imported with ownership not resolved.
  3. Hunto adds the findings to your detections automatically, so they de-duplicate against what you already have.
  4. A message reports the outcome.
Message Meaning
"Recorded N finding(s) as a discovery." New findings were added.
"Already known: N finding(s) merged into existing detections." They matched detections you already had.
"Nothing was imported." Every row was refused. No discovery record is created.

Note: Imports do not use credits and do not run any checks. They only record what you supply.

Note: Imported findings are not closed automatically when a later attack surface run stops seeing them. Close them yourself when they are resolved.

Use cases and wiring tips

  • Bring in a pen test. Put each finding on a row with Classification, Value, Target and Severity, upload it, and track fixes in detections and tasks.
  • Record a takedown lead. Use Add one for a phishing site a customer reported.
  • Wiring. Imported findings appear in All Detections and count in your security score like any detection.