Reading a story

A Story is one of the core components of the Hunters SOC Platform, providing an intuitive way for any security analyst to easily consume multiple leads which were correlated on the Hunters graph. This page explains the different controls within a Story, and how to consume it in order to effectively triage correlated leads in the environment.


Story interface

 


General Options


General options for further view settings and personalization

 


#Description
1Copy the Story's URL and view the Story in full screen
2Copy the Story's full UUID to the clipboard
3Zoom in/out, as well as view the Story in full screen
4Bookmark a Story for later usage. Bookmarked stories can be accessed through the Bookmarks tab on the top right of the Stories page
5Comment and collaborate on the Story, including tagging other team members and uploading files
6Indicates whether this story is the most current and updated version or if a more updated version is available. Stories may evolve over time as new signals are detected in the environment. The logic behind the evolution of stories is described in more detail later on this page


Triage


Triage options that allow control of the Story 

 


#Description
7Add a title and description to the Story
8Tag a Story and assign it a label. Options are Pen-Testing, Red Team, Bad Practice, Malicious, Authorized Activity, Irrelevant Correlation
9Set the Story status. Options are New, WIP (Work in Progress), Done, Reopened
10Batch classification of all leads in the Story
11Assign the Story to an analyst
12Change the Story layout. Options are Network, Network-Hierarchy, Raw Network, Story (default layout). Working with the different layouts provides a better understanding of the underlying correlation
13Change grouping by Detector or Entity
14Filter the Story view based on leads from specific detectors
15The Story's score
16Display all leads that are part of the Story



Story content


The core components of the Story 

 


#Description
17The time between the first lead to the last lead in the story
18Timeline view of the Story. Hovering over specific leads will indicate their position on the Story timeline
19The score of the particular lead (based on Risk Score feature)
20The detector that generated the lead
21The data source used to generate this lead
22Indicates the lead's investigation status (Open, WIP, Done)
23Open the lead in grid view, hone in, or hide it from view
24Entities that are part of the story. Hover over the entity for additional information
25How leads are correlated (related entities), showing as direct (purple line) or indirect (grey line)