Platform

Monitor and optimize your discoveries

Once your discoveries are running, use this page to keep them working: watch what changes, keep the noise down and spend credits where they matter.

Monitor what is happening

You want to know Where to look
Is a run still working? Discoveries, Runs tab. The status pill shows queued, running, paused, stuck, success, partial, failed or cancelled.
What did it find? The run's Findings tab
What is new since last time? The run's Changes tab, or the Changes feed in Monitoring
Which schedules will fire next? Discoveries, Schedules tab, Next run column
What is waiting for me? Potential Detections, Open tab
How is a domain trending? The domain's rating History

A run is marked stuck when it has made no progress for more than an hour. Open it and select Refresh. If it still does not move, select Stop run. Finished work is kept and rated. See How a discovery run works.

The Changes feed

Hunto compares each finished run with the previous run of the same schedule and records the differences as changes. Kinds of change include:

  • appeared and disappeared hosts or services
  • ports opened and closed
  • technology changes
  • certificate changes
  • address changes
  • score increases

Each change has a significance so the important ones sort to the top. Use it as your weekly review list instead of reading full runs.

Read the signals correctly

  • A Not measured section means Hunto could not look, not that it is clean. Run again later or use a different detective.
  • Failed and not run counts in the run header tell you how much of the plan did not complete. A high count with few findings is an incomplete picture. See Discovery concepts.
  • Gone in Changes may mean a source timed out. Confirm before treating something as fixed.

Optimize for quality

  1. Start narrow. Begin with Outside-in rating or one focused detective. Add Attack surface or Brand & leaks when you are ready for more results.
  2. Review results regularly. In Potential Detections, use Not real and Out of scope for noise, with the closest dismiss reason. Repeats of a dismissed finding are closed with it.
  3. Prefer focused detectives on a schedule. Lookalike domains and Leaked credentials are quick and easy to read. Keep Full sweep for your own domains, occasionally.
  4. Save the sets that work. In Advanced, save a checks selection as a detective and reuse it. See Detectives.
  5. Keep filtering on Tag it, keep it for detectives you create, so nothing disappears silently.

Optimize for cost

Change Effect
Slower Repeat Fewer runs, fewer credits
One Advanced run for many targets One charge for the whole selection
Simple mode within 24 hours Reuses a finished run for free
Turn Repeat to Off on old schedules Stops charges
Turn off automatic rating of new domains No charge for domains you do not need rated

Details are in Credits and limits for Discovery.

Tune depth

A detective's Max depth is how many follow-up rounds it runs. Each round takes what was found and looks further.

  • Raise it (up to 10) for a full investigation of a complex estate.
  • Lower it for faster, smaller runs.
  • Max fan-out limits how many new targets a single check may add. Lower it if runs grow too large.

Changes apply to future runs only.

Keep the whole picture connected

  • Turn on notifications for new detections so a sweep does not depend on someone opening the page.
  • Add the findings that matter to detections. Only then can they be assigned, become tasks and feed reports.
  • Use Report (PDF) on a run, or the assessment report from Runs, to share status.

Use cases and wiring tips

  • Weekly brand-abuse sweep. Schedule Brand & leaks weekly. Each Monday open Potential Detections, filter Anything new and work from Worst first.
  • Watch a score dip. Schedule Outside-in rating weekly. When the grade drops, open the newer run's Changes tab, then add the cause to detections and create a task.
  • Vendor check. Run Outside-in rating Once on a vendor's domain before each review. Compare with last time using the Run switcher.
  • Wiring. Discovery feeds assets, detections, incidents, tasks, notifications, reports and the security score. See Discovery use cases and wiring tips.