Platform

Asking Hunto to check a finding

Sometimes a finding needs a second pair of eyes: is this really a phishing site, is this exposure real, is this classification right? Ask for a check lets you put that question to Hunto from the finding itself. The request becomes a task, is picked up by a person or an automated checker, and the answer comes back on the finding. Nothing about the finding is changed for you; the answer is advice you can act on.

Where to find it

Open a detection (for example from Brand Protection or the threat lists). In the pane on the right there is a section called Ask for a check, with the hint "A person or an agent picks it up". It shows one button for each kind of check that makes sense for that finding's type, and the requests already made.

Asking

  1. Open the finding and find Ask for a check.
  2. Choose the check you want. The buttons are worded as a question, for example Verify this credential or This classification looks wrong.
  3. Fill in the small form. Some checks ask for something specific (for example the credential to test, or which classification you disagree with). The optional Why you are asking box helps whoever picks it up.
  4. Choose Send request.

You see "Requested: ". If the same check is already open for that finding you see "Already requested — that request is still open" and nothing new is created; the button for that check stays disabled with "Already requested — see above" until the first one is finished.

Only findings that belong to your organisation can be checked.

The checks on offer

Which checks are offered depends on the type of finding.

Check For What it does
Validate this threat Phishing, scam, counterfeit, rogue application, social media, advertisement Confirms whether the finding is a real threat.
Is this ready for takedown? The same types Checks the evidence is enough to file a takedown.
Verify this exposure Subdomain, IP address, service, open port, domain Confirms the exposure is real and reachable.
Confirm this is ours Technology, certificate Confirms the asset belongs to your organisation.
Re-run this check Vulnerability, information disclosure, code exposure, sensitive information Runs the detection again to see whether it still applies.
Verify this credential Leaked credentials, dark web, breach data Checks whether the leaked credential is still valid. You are asked whether you recognise the account. This check is currently answered by a test (mock) checker only; see below.
Analyse APK (thorough) Rogue application Deeper analysis of a suspect app. Currently mock only.
Check it is fixed Subdomain, IP address, service, open port, vulnerability, information disclosure, code exposure, sensitive information You say what you changed; a person checks it worked.
The classification looks wrong Any type Asks a person to review the classification. Needs a reason.
Prepare takedown Phishing, scam, counterfeit, rogue application, social media, advertisement A person prepares the takedown notice; you can say what it must include.

What happens next

The request is a task with the type "review". You will find it in Tasks like any other. It moves through these states:

State Meaning Task status
Requested Waiting to be picked up. Not assigned
Being worked Someone or something has accepted it. Not started
In review The work is under way. In progress
Needs input The checker has a question for you. The question is held on the task; there is not yet a reply box on the finding, so if a request stays here, contact your Hunto contact. A new request for the same check is refused while this one is open. In review
Completed An answer is in. Completed
Declined The request was turned down, with a reason. Rejected

Each request in the list shows its state, who is working on it ("Waiting to be picked up", or the person or agent name), how long ago it was requested and, once done, the verdict and the comment. Completed and declined are final; to ask again, send a new request. While a request is open (requested, being worked, in review, needs input), asking for the same check again just points you at it.

An answer gives a verdict (for example confirmed, not confirmed or inconclusive), what was found and the evidence. It is a recommendation: the finding itself is not changed automatically. You decide whether to accept the advice and, for instance, change the finding's status.

A person can also review a completed answer, either confirming it or correcting it with a reason. That feedback is how the checks get better.

Test answers are labelled

While some automated checkers are still in testing, their answers carry the warning "MOCK — not a real check". Do not act on them. The credential and APK checks are in this state at the time of writing.

No service level yet

Review requests do not currently have a promised response time, and there are no due dates on them. If a request matters urgently, say so in Why you are asking and mention it to your Hunto contact. Requests are worked oldest first within each kind.

Using the task

Because a review request is a task, you can:

  • find all of them in Tasks by searching for the finding ID, or with the Team filter (review tasks carry the team "hunto-ai");
  • comment on the task, or watch its activity;
  • count them in Task Analytics like any other task.

Please do not close a review task by hand to make it go away; the requesting side treats that as an answer. If you asked by mistake, let the request run to completion or ask your Hunto contact to decline it.

Permissions

Any member of your organisation who can see monitoring findings can ask for a check. From an AI assistant, requesting a review needs the tasks:write permission; see Tasks from an AI assistant or script.