Pulse Intelligence hunts are structured indicator queries. They are designed for repeatable analyst workflows: define a condition set, preview current matches, schedule it, and alert only when new indicators match.
The builder supports:
all matching for AND logic and any matching for OR logic.Whitelisted indicators are never matched by hunts.
Templates are starting points. Review the conditions before saving and tune dates, tags, and confidence thresholds for the environment.
The builder and hunt detail page generate portable query drafts for:
These drafts target normalized Pulse indicator fields such as type, value, severity,
confidence, tags, source, attack.technique, and attack.tactic. Adapt field names to
the destination SIEM schema before production use.
Saved hunt matches can be exported from the hunt detail page. The export reuses the same safe indicator formats as the main IOC export flow:
Exports are capped to protect the web process from very large downloads. Streaming exports are tracked in the roadmap for large deployments.
Scheduled hunts compare the current match set against the previous run. Alerts are created only
when a hunt has Alert on new matches enabled and new indicators are found.
A first run treats all matches as new, which establishes the hunt baseline.