Platform

How a discovery run works

This page follows one run from the click to the finished report, so you know what each status means and what you can do while it runs.

The life of a run

  1. Start. You select Run discovery. Hunto checks the target, checks that you have enough credits, then creates a schedule and a run. If the same run is already going, or finished in the last 24 hours (Simple mode), Hunto shows that one instead and charges nothing.
  2. Plan. Hunto works out which checks apply to your target. A check that cannot apply to it, for example an email check on a host, is skipped as does not apply to this target.
  3. Run the checks. Checks run in the background. Some produce new targets that are checked in later rounds, up to a limit set by the detective.
  4. Collect findings. Results arrive while the run is live. The run page refreshes every 10 seconds.
  5. Rate. When the run finishes, Hunto computes the rating from the checks that feed it. Until then the grade is marked provisional.
  6. Compare. Hunto compares the run with the previous completed run of the same schedule, so you can see what appeared, disappeared or changed.

Run statuses

You see these in the Runs tab and on the run page.

Status Meaning
Queued Waiting to start.
Pending The schedule fired but no results have arrived yet.
Running Checks are in progress.
Paused No new checks start until someone resumes. Checks already in flight finish.
Stuck No progress for over an hour. Contact support if it stays in this state.
Success Every check finished without error.
Partial The run completed, but some checks failed.
Failed Every check failed, or the run could not start.
Cancelled The run was stopped before its work was done.

The run page also uses Running, Paused, Completed, Stopped and Failed in the status chip at the top.

The Outcome column shows how many findings the run produced, the number of checks that worked ("N ok") and, in red, the number that failed. Select a red count to open the run.

What you can do while a run is live

On the run page:

  • Pause stops new checks from starting. Resume continues.
  • Stop run skips the checks not yet started, keeps what is finished and rates the run from it. Hunto asks you to confirm.
  • Refresh reloads immediately.

Tip: Credits are charged when a run starts, so stopping a run does not change the charge. See Credits and limits for Discovery.

Why a check may not run

The run header shows how many checks failed and how many were not run. Common causes:

Cause What it means
Already ran on this target The same check was already done on the same target in this run, so it is not repeated.
Does not apply The check does not accept this kind of target.
Past the depth limit The check would have followed one more lead than the detective allows.
Stopped by a person Someone paused and stopped the run, or skipped work.
Failed The check, or the source it reads, returned an error.
Source did not answer The check ran but its data source gave no answer, so an empty result may be a miss.

Hunto support can see the per-check detail. Send them the run id from the page address if you need it.

Note: A check whose source did not answer is treated as "could not look". It is never shown as clean. See Discovery concepts.

Repeating runs

A schedule with Daily, Weekly or Monthly starts a new run each time it fires. Every run checks your credit balance first. If the balance is too low, that run does not start. See Schedules and repeating discoveries.

Use cases and wiring tips

  • Watch a live run. After starting, select Open the run. The Findings tab fills as checks finish.
  • Investigate a failure. In Runs, select the red failure count. If a check keeps failing, contact support with the run id.
  • Compare runs. Open the Changes tab on a run to see what moved since the last run of the same schedule. Use it to confirm that a fix worked.
  • Wiring. The finished run's rating goes to the Security Posture page. Its findings go to the Potential Detections queue. See Findings, potential detections and triage.