Home
Elezar

Autonomous
Threat Hunting

Threat-led hunting at a scale your team couldn’t reach alone.

Define the scope.
Let Sol take it from there.

Sol gives SOCs and MSSPs autonomous, intelligence-led threat hunting. New reports entering your Threat Profile trigger hypothesis-driven investigations across your connected integrations. You choose where Sol investigates and when each hunt plan needs approval.

  1. 01

    Create a Threat Profile.

    Focus the intelligence Sol collects on the threats relevant to your organisation.

  2. 02

    Set your automation.

    Choose the integrations Sol hunts across. Run automatically, or approve each hunt plan before execution.

  3. 03

    Review the results.

    Inspect the findings, supporting evidence and recommended next steps, with the investigation detail close at hand.

Every hypothesis.
Every finding. Open to review.

Explore examples from Sol’s hunt plans, assessments and findings. Each view shows a different part of the work your team can inspect.

01 / INTELLIGENCE TO HYPOTHESES

Hunt how adversaries operate.

Sol turns relevant reports into detailed hunt hypotheses, organised by attack path and mapped to ATT&CK tactics and techniques. Each hypothesis gives the investigation a specific behaviour to test.

Hunt hypotheses mapped to tactics and techniques for a SharePoint-lure attack path
An example hunt plan: hypotheses grouped by attack path, with their tactics and techniques.

02 / EXECUTION & EVIDENCE

Follow the investigation.

See the basis for each assessment, the observations behind it, and the queries and results used to investigate. Your team can inspect how Sol reached its conclusion.

Hypothesis assessment with observations, Sentinel query and returned evidence
An example assessment: observations, query details and source reads, including a failed read and a subsequent result.

03 / FINDINGS & NEXT STEPS

Know what needs attention.

Review findings with severity, supporting context and recommended next steps. Follow each finding back to its source hunt, with a clear distinction between what was observed and what remains unproven.

Detailed finding showing severity, evidence limitations, recommended actions and source hunt
An example finding: observed connections, an explicit evidence limitation and recommended investigation and detection actions.

04 / VISIBILITY & COVERAGE

See the gaps, too.

Bring findings together across your Threat Profile. Review suspicious activity alongside gaps in telemetry that limit what Sol can assess, so your team knows where further investigation or visibility is needed.

Threat Profile findings overview with impact levels, source hunts and recommended actions
An example Threat Profile overview: findings and visibility gaps, organised by impact with suggested actions.

Choose how and where
Sol gets to work.

Set the automation mode and choose the connected integrations Sol hunts across.

Mode

Decide when your team approves a hunt.

Fully automated

New intelligence triggers hunt planning and execution without requiring approval of each plan.

Approve before execution

Sol prepares the hunt plan. Your analyst reviews and approves it before the hunt runs.

Run targets

Choose where Sol looks for evidence. Select connected integrations for each Threat Profile.

Explore integrations
Threat Hunting settings with Fully automated selected and Microsoft Sentinel and GitHub selected as connected run targets.
Choose your automation mode and the integrations Sol hunts across.

From intelligence
to findings.

Results from one customer Threat Profile over one month.

FOCUS

Threat reports triaged
420
Reports found relevant
42

INVESTIGATE

Hunts executed
51
Attack paths
191
Procedures tested
744

REVIEW

Findings identified
21

Evidence and next steps, ready for the team to review.

“Elezar’s Sol gives me greater insight into risky behaviour and complex threat actor techniques without having to put six figures of salary on the task. We rely on Sol to be looking when we can’t, and bring what matters to our attention.”
CEO and Chief Solution Architect · OpusVCritical Infrastructure Technology and Cybersecurity Provider

Put your threat
intelligence to work.

See how a relevant report becomes a hunt plan, an investigation and findings your team can act on.

Book a demo