01 / INTELLIGENCE TO HYPOTHESESHunt how adversaries operate.Sol turns relevant reports into detailed hunt hypotheses, organised by attack path and mapped to ATT&CK tactics and techniques. Each hypothesis gives the investigation a specific behaviour to test. An example hunt plan: hypotheses grouped by attack path, with their tactics and techniques.
02 / EXECUTION & EVIDENCEFollow the investigation.See the basis for each assessment, the observations behind it, and the queries and results used to investigate. Your team can inspect how Sol reached its conclusion. An example assessment: observations, query details and source reads, including a failed read and a subsequent result.
03 / FINDINGS & NEXT STEPSKnow what needs attention.Review findings with severity, supporting context and recommended next steps. Follow each finding back to its source hunt, with a clear distinction between what was observed and what remains unproven. An example finding: observed connections, an explicit evidence limitation and recommended investigation and detection actions.
04 / VISIBILITY & COVERAGESee the gaps, too.Bring findings together across your Threat Profile. Review suspicious activity alongside gaps in telemetry that limit what Sol can assess, so your team knows where further investigation or visibility is needed. An example Threat Profile overview: findings and visibility gaps, organised by impact with suggested actions.
Fully automatedNew intelligence triggers hunt planning and execution without requiring approval of each plan.
Approve before executionSol prepares the hunt plan. Your analyst reviews and approves it before the hunt runs.