Black Hat USA Aug 4-6, Mandalay Bay. Book time with us
Solutions · Threat Hunting

Hunt with an agent that already knows how to look.

So what does Soarcery do for threat hunting? Ask the Familiar a plain-English question about an entity, and it investigates across your stack the way an analyst would, with the plan shown before anything runs.

The problem

Most hunts die in the setup.

A hunt starts with a hypothesis and ends in console hopping: pulling telemetry from five tools by hand just to prove or disprove it. By the time the context is assembled, the hour is gone and the hypothesis is cold.

Hunts die in the setup

Five consoles, five query languages, one hypothesis. Most of the hour goes to assembling context, not testing the idea.

Hypotheses go cold

By the time the telemetry is stitched together, the moment that raised the question has passed.

Findings scatter

What the hunt turned up lives in a notebook, a screenshot, and someone's memory. None of it survives to the next hunt.

How Soarcery does it

Ask in plain English. Get the legwork done for you.

1

Pivot on an entity, or just ask

Give the Familiar a hash, an IP, a username, or a hostname to pivot on, or ask a free-form question like "what is happening on host LON-4471 right now?"

2

It plans, then investigates across your stack

It shows the plan first, the tools it will use and its assumptions, then pulls context across endpoints, identity, email, cloud, and tickets into one case.

3

Findings land on one record

Every correlation and enrichment keeps its evidence attached on one exportable, replayable trail, ready to become a Spell if the hunt turns into a repeatable pattern.

4

A good hunt becomes a Spell

When a hunt turns into a repeatable pattern, it can be saved and re-run, so the next occurrence is caught without re-deriving the idea.

In the product

From a question to an investigation.

Asking the Familiar: a plain-English question or a one-shot action, with the thread of previous asks alongside, demo dataAsking the Familiar: a plain-English question or a one-shot action, with the thread of previous asks alongside, demo data

Actual product. Demo data.

The ask

State the hunt the way you would say it out loud. No query language to remember, no console to log into first, and the plan is shown before anything runs so you can correct the approach rather than the results.

The legwork

The Familiar pulls the context the hunt needs across endpoint, identity, email, and cloud, and posts each finding to one case as it lands. The hypothesis gets tested while it is still warm.

The Familiar working a live case: findings posted to the investigation thread, demo dataThe Familiar working a live case: findings posted to the investigation thread, demo data

Actual product. Demo data.

Where this is different

Hunting without the console hopping.

  • Plain English in, real investigation out: no query language required to test an idea.
  • The plan shows first: what it will search and what it assumes, before anything runs.
  • Findings land on one record, exportable and replayable, not scattered across tools.
  • Anything consequential still stops at the Seal, evidence attached.
Bring your hypothesis

Hunt on your real telemetry.

A 30-minute walkthrough on your real stack. Ask the Familiar the question you have been meaning to chase down.