---
title: "What is Hunters SOC Platform?"
slug: "what-is-hunters"
description: "Hunters SOC Platform empowers security teams to automatically identify and respond to incidents that matter across their entire attack surface."
updated: 2025-03-11T08:56:50Z
published: 2025-03-11T08:56:50Z
canonical: "docs.hunters.ai/what-is-hunters"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hunters.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# What is Hunters

Hunters SOC Platform helps security teams quickly detect and respond to important threats across their entire attack surface. With built-in detection engineering, data correlation, and automated investigations, teams can tackle real threats faster and more reliably than traditional SIEM. This ultimately reduces overall security risks.

## Hunters pipeline

Hunters SOC Platform runs on an advanced data pipeline that ingests all your security data and extracts valuable, actionable signals. The Hunters pipeline contains four main steps:

### Ingestion

The first phase of the Hunters pipeline is gathering your organization’s security data. At this stage, the platform collects data (such as accessing a security product’s REST API), transforms it, and stores it in the data lake.

📘 Learn more

[Deep dive](https://docs.hunters.ai/v1/docs/ingestion) into Ingestion

### Detection

In the second stage of the Hunters pipeline, the system identifies suspicious events in your organization's raw data. Each Data source—such as AWS, CrowdStrike, or Active Directory—has built-in Detectors that generate Leads based on predefined rules. You can adjust these detectors or create custom ones to fit your organization's needs.

📘 Learn more

[Deep dive](/v1/docs/detection) into Detection

### Automatic investigation

Hunters automatically investigates leads detected in the pipeline. It gathers more data on specific Entities, Attributes, and the lead itself. The system then assigns a Risk score to help your team focus on real threats and filter out noise.

📘 Learn more

[Deep dive](/v1/docs/automatic-investigation) into Automatic investigation

### Correlation engine (Stories)

In the final stage of the Hunters pipeline, the system connects related leads to a specific security incident. It automatically maps all data points within the same attack flow and compiles them into a clear, comprehensive Story for your team to review in one place.

📘 Learn more

[Deep dive](/v1/docs/correlation) into Correlation

A Security Operations Center (SOC) platform is a set of integrated tools and technologies used to monitor, detect, analyze, and respond to security incidents and threats across an organization's IT infrastructure.

A product we can integrate with to ingest logs.

A specific piece of logic used to generate leads from a raw data integration (previously named Analytic). Most detectors are built-in by Hunters for each integration, but you can add custom ones through the Custom Detector wizard.

A lead refers to a potential security incident or threat that has been identified through security monitoring activities or other sources of security intelligence.

Entities are objects or systems that can be targeted by an attacker or that can participate in a security event. Entities can include devices, applications, networks, users, and data.

Attributes are fields attached to a lead that provide more information about the incident described in the lead. A lead can have many attributes such as "domain: hunters.ai", or "remote_ip: 10.0.0.1".

Risk score is a measure of the overall risk associated with a security threat or incident. Hunters Risk Score is calculated based on a combination of factors, including confidence and severity.

A story is a collection of leads that are strongly related and likely to be a part of the same attack flow.
