Threat Hunting

Overview

Seqrite Universal Agent continuously monitors all activities on your machine and generates events in EDR. These events are evaluated against the rules defined in EDR. If an event matches a rule, an alert is generated. Events that do not match any rule are not ignored—they are stored in Threat Hunting for further analysis.

Threat Hunting enables detection and monitoring of events that are not yet documented in Seqrite or included in the rule builder. This feature helps track new or unknown malicious activities emerging in the cyber world.

Alerts generated from unmatched events are displayed under the Alerts tab.

Raw events are stored under the Processes tab.

Independent of rule creation or alert generation, users can proactively hunt threats using this feature.

Threat Hunting Interface

The Threat Hunting screen provides two search options:

  • Manual Search
  • File-based Search

Data Retention

  • Alerted events: retained for 30 days
  • Raw events: retained for 7 days

Manual Search

The Manual Search tab allows you to search events using filters and parameters.

  • Use the search bar with View and Host filters.
  • Add parameters, select the view period, and choose a host from the dropdown.
  • Search results are displayed under the Alerts and Processes tabs.

Actions

  • Export Results: Use Schedule Export or Export buttons to download search results.

  • View Event Details:

    • Select a raw event to open its details in the right panel.
    • Click View details to access the Timeline page.
    • The timeline displays a tree structure of the event’s generation history.
    • Apply filters in the search bar to highlight specific information.

This detailed view helps determine whether an event is malicious and supports deeper analysis.

File-Based Search

The File-based Search tab allows bulk searching using a CSV file.

  1. Download the sample CSV template.

  2. Add desired details under the following headers:

    • IP Address
    • URLs
    • Domains
    • Hash Values
  1. Upload the CSV file to conduct the search.
  2. Uploaded files are listed on the File-based Search screen and can be used to run searches.

Creating a Query

To create a query, follow these steps:

  1. On the Seqrite EDR portal, click the Threat Hunting page in the left navigation pane. The Threat Hunting tab is highlighted with a yellow square. You can directly search using appropriate search parameters or create a new query using the query builder.
  2. Click the Add + button to add the filter values. The Filters dialog box is displayed.
  3. In the Search textbox, click and select from the filters that are displayed.
  4. Enter the value of the filter that you want to use in the search query. For example, Name. The filter is selected and displayed in the Search box, enter a value for the indicator. For example, we shall add Name: Powershell.exe
  5. Click Add+ to add the selected IOC and the search value. The value is selected and displayed under Selected Filters.
  6. Click in the Search box and repeat above steps to add other IOC values for the search query. For example, and IP address IP:”202.145.202.114”.
  7. Add more IOC as required. To remove a particular filter, click the corresponding x mark for that value.
  8. Click Apply to apply the search criteria.
  9. Once you are done with adding the filters and their values, click Save Query. The query is saved with time stamp and moved to the Saved Queries tab.
  10. Enter a name for the query in the Query Name column (highlighted in the yellow box). For example, Powershell+IP, and click Save. A confirmation message is displayed and the query is saved.

Using Saved Query to create a new query

  1. On the Seqrite EDR portal, click the Threat Hunting page in the left navigation pane. Click Add+. The Filter dialog is displayed.
  2. Click the Saved Queries tab. The saved queries are displayed in order of the created timestamps.
  3. Scroll down the query list, or use the sort icons besides the Time Stamp and Query Name columns to sort entries as required. Select the query that you want by clicking on the query. The query tags are displayed in the Query tags section for the selected query.
  4. To add the Filters from the selected query to a new query, click Add Filters. The query is moved to the Add Filter tab and 2 extra buttons, Update Query and Save Query are displayed.
  5. To update the query, add/remove filters as required and click Update Query.
  6. To save as a new query, click Save Query. If you click Save Query, the query is moved to the Saved Queries tab.
  7. Enter a name for the query in the Query Name column, and click Save. A success message is displayed and query is saved.

Deleting Saved Query

You can delete the saved queries if not required.

  1. On the Seqrite EDR portal, click the Threat Hunting page in the left navigation pane.
  2. Click Add +.
  3. On the Filter dialog box, click Saved Queries. The saved queries are listed.

Running a Query

You can create a new query with required indicators and apply the query to get results or you can use previously saved queries to search for threats in the Seqrite EDR database.

  1. On the Seqrite EDR portal, click the Threat Hunting page in the left navigation pane.
  2. Click Add+. The queries filter dialog is displayed.
  3. Create a new query or click the Saved Queries tab to view the Saved Queries and select the query that you want to run. For this example, we click on Saved Queries tab and select the first query in the list.
  4. Click Add Filters, to add/modify and filters in the selected query.

As a result of previous action, some indicator filters are displayed. Add or remove the indicator filters as required.

  1. Click Apply to run the final query. The results are displayed in two tabs: Alerts and Processes. The Alerts tab displays the alerts that match the query, and the Processes tab similarly displays the matching processes.
  2. Running a saved query
  3. To obtain more information about an alert, click the alert row.
  4. To view the Process details for that host, click the Process tab on the upper left corner. The details for only the processes that match the query are displayed.
  5. To start the investigation for a process, click the particular process.

Search History

The search History tab displays all the search queries carried out recently. You can use a query from the recent queries or applied queries.

  1. On the Seqrite EDR portal, click the Threat Hunting page in the left navigation pane.
  2. Click Add +.
  3. On the Filter dialog box, click Search History. The recently run queries are listed.
  4. Select the query you want to apply. Modify the query if required.
  5. Click Apply. The query is applied, and search results displayed.

Note:
There is fix list of parameters for which you can do threat hunting. If such parameters are present as key attributes for any of the incidents or alerts you can do threat hunting from that incident’s Page or alert’s Page respectively.

 

Was this page helpful?