---
title: "Person Matcher"
slug: "person-matcher"
updated: 2026-01-25T09:31:11Z
published: 2026-01-25T09:31:11Z
canonical: "docs.hunters.ai/person-matcher"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Person Matcher

The Person Matcher is a type of enrichment used to connect user names and email addresses when running investigation and correlations during the Auto investigation phase of the data.

📘 Learn more

[Learn more](/v1/docs/automatic-investigation) about the Automatic Investigation phase.

It allows the system to connect a user and their accounts by using known names, usernames and email addresses, which provides context to Lead Entities.

In order for a person matcher to work, you must have a valid user data source connected. This can be (but not limited to): Active Directory file, Azure Entra ID Users, Okta Users, etc.

💡 Activate the Person Matcher

To activate the Person Matcher enrichment, contact Hunters Support.

The investigation phase is responsible for the curation and prioritization of the threat signals.

A lead refers to a potential security incident or threat that has been identified through security monitoring activities or other sources of security intelligence.

Entities are objects or systems that can be targeted by an attacker or that can participate in a security event. Entities can include devices, applications, networks, users, and data.
