---
title: "Search for entities"
slug: "search-for-entities-1"
updated: 2025-03-05T17:06:21Z
published: 2025-03-05T17:06:21Z
canonical: "docs.hunters.ai/search-for-entities-1"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Search for entities

## About Entity Search

The Entity Search allows you to search for various entities using different identifiers such as host names, user names, IP addresses, etc. over Hunters data. Use the Entity Search to find and visualize the presence of specific entities throughout the system. This will allow you to scope the entity’s involvement in incidents and understand its presence in the Hunters data.

The Entity Search tool is designed to provide in-depth and comprehensive results, including leads and stories the entity is involved in, as well as enrichments added to the entity as a result of the automatic investigation process. Additionally, when searching for host names, the Entity Search will present a complete list of events related to the searched host. To display this level of detail, the tracker is limited to a single entity at a time.

⚠️ AttentionThe Event results are currently limited to hosts, with the bulk of the information arriving from EDRs.

## Search for entities

**To search for entities:**

1. From the Hunters platform menu, navigate to **Investigation > Entity Profile**. ![](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Entity profile menu item.png)
2. In the search bar, search for an entity by ID, name, address, etc. ![](https://lh7-us.googleusercontent.com/docsz/AD_4nXfmyR2h-ABLWuFLqsZTbNb6YRMBeDQUKMRzf8Q5x7hP8Lhgt0iBTRLlZ7JpsVnbdX9Rwk-eM88S6Ll35KoDMJz7orSdDfW26WtA2cAJ--__VxE8-aPKNiLqUZEk98MwSE6BlT9848_oCcqgqMY5ylH6cRBe?key=Q2xlaNwuI2rFMigo4Z-57w)

> [!NOTE]
> 💡Tip
> 
> 
> 
> Type text to find entities that contain it:
> 
> | Searching | Will match |
> | --- | --- |
> | ric | Rich, Eric |
> 
> 
> 
> Use quotes (") to find the exact text:
> 
> | Searching | Will match |
> | --- | --- |
> | "rich" | Rich |
> 
> 
> 
> Use asterisk (*) to match any part of the text:
> 
> | Searching | Will match |
> | --- | --- |
> | r*c | Rich, Eric, Rachel |

1. Select the most relevant item from the suggested list of results. Note that suggestions are divided into different types of entities and that the total number of results is specified under the list. ![](https://cdn.document360.io/5f63f0e0-3c70-4d00-b623-82493be0bde5/Images/Documentation/Entity search results.png)

> [!NOTE]
> 💡Tip
> 
> Search for entities directly from a Lead or cluster by clicking on the entity name from the Lead details, and then selecting Investigate. ![](https://lh7-us.googleusercontent.com/docsz/AD_4nXcojQ9EXIhF3-JeJpQhxmFSOsTzLx8BSqzBsI_rLfclFxhNPASByOIQ446CR-N0kC4UqKg4AwlApl6XNRXumPmkBCoPF0gPQKOwIH4SXtygVvYvieeEsd22MzNDu-tRJCp5pjiXgqijzAyMTAjRdHpFV6RK?key=Q2xlaNwuI2rFMigo4Z-57w)

## Investigate search results

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXd0q5BjcZF4PxyU7ITxJ5WxdFFwaTBJptyvj10F0h-P6lEbZ8kJx0mmmwxyTpxiRIvXdSFH7U_l2nt9UnbA-TalP6gzU_XbwTvVTq9o1cjwYdZCpyrnfzm4-3g-d1CgnOe0Ra5p-hh4PJikbeg_Wcn96-mb?key=Q2xlaNwuI2rFMigo4Z-57w)

Entity Search results are separated into 3 tabs, each providing the complete picture of the entity, depending on the type of information selected:

- **Leads and Stories** - this tab displays all leads and stories involving the searched entity from the past 6 months.
- **Enrichments** - this tab displays enrichments and other entities related to the searched entity from the past 6 months.
- **Events** (only for hostnames) - this tab displays all events involving the searched entity (even those not part of a lead), from the selected time frame. ![](https://lh7-us.googleusercontent.com/docsz/AD_4nXcFx0irLH_MwxZ-HpJiKV_GxfHRW65ORQ_ipjecduxeCCJ_bH-RzjuNazJFfVifEw-rBt7Qq_BUX3msj9pmJwBWl4KzZ1AHDfOEwauYpxB68jLdSrKb7AKuSTBlUIUw92n1sSvkQri84iOH1suQEOcIMeFP?key=Q2xlaNwuI2rFMigo4Z-57w)

> [!NOTE]
> 📘Learn more
> 
> Events are an elaborate topic which is covered in [Explore entity events](/v1/docs/explore-entity-events).

### Leads and Stories

The Leads and Stories tab displays all leads and stories involving the searched entity from the past 6 months.

Leads are displayed in clusters, including the Cluster context, and can be triaged like any other leads straight from the search results page.

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXdODX6SNU1GFCb3oEY-hnM8cC6Z51JSA7_8UDkBXZSHDbCFPsr5XSybSjHX0pIbG1JJgl8FAosxvpbmGrnGDlgr09J9_A98INWQEZB2o6RTr0QJ3re_V1ztAhKykkZHNB48616U6mlSH2GHAIH_xd4oj6fu?key=Q2xlaNwuI2rFMigo4Z-57w)

> [!NOTE]
> 📘Learn more
> 
> - Triaging leads
> - Triaging clusters

Stories are displayed with all relevant details, including score, Story timeline, layout options, and more. You can triage the story, assign it to a team member, add tags, and more.

![](https://lh7-us.googleusercontent.com/docsz/AD_4nXcJNX6LmkAgabm8HFA5-lEQN-Xhzu2qYdtqh8gWbQb5v0RX0MfVdtWGcbF6Zi0bX-aCVXzZar5nMH5YQMaoidYWpn2I1O4uQubCQjlgnMUp6ujwHn2LdW3A_2mSnOf3VLHV9QkH8kgNEaWDSVh1Qedxx6W8?key=Q2xlaNwuI2rFMigo4Z-57w)

### Enrichments

The Enrichments tab displays 2 types of information:

- **Related entities** - A list of all entities strongly correlated to the searched entity, based on findings from the Stories graph. In this section you can also explore an interactive network diagram, demonstrating the connection between the searched entity and the related entities. The searched entity appears in purple. ![](https://lh7-us.googleusercontent.com/docsz/AD_4nXdhrtLN-mYrS-vgsKHFHQJ779jMdbZVsGkceXkLANiAnwnUt3WnGcJUywZaSK-XMEbME2PYRVcx36vYLnXf-qRkY2-c-mktY6DZwF6rTf18WX_rrzjMyvpuIWquCbpmC93mXIV9LY2n0HyMBSUF2-WyZCe7?key=Q2xlaNwuI2rFMigo4Z-57w)
- **Drill-downs** - Showing results of drill-downs that had this entity as an input from a recent lead.

An entity refers to any object or system that can be targeted by an attacker or that can participate in a security event. Entities can include devices, applications, networks, users, and data.

The automatic investigation phase is responsible for the curation and prioritization of the threat signals.

A lead refers to a potential security incident or threat that has been identified through security monitoring activities or other sources of security intelligence.

The cluster context provides the rationale behind the grouping of specific leads under one cluster. The cluster context displays the common attributes of the leads below the cluster.

A story is a collection of leads that are strongly related and likely to be a part of the same attack flow.
