HuntSQL is a query interface designed for security researchers and analysts to use standard SQL for searching Hunt Intelligence's threat datasets. It provides direct access to a database of historical and active malicious infrastructure, enabling users to run precise queries. The accessible datasets include first-party HTTP data, confirmed command-and-control (C2) servers, SSL/TLS certificates, honeypot activity, open directories, and phishing sites.
The purpose of the capability is to facilitate threat hunting and analysis at scale. By utilizing SQL-based investigations, security teams can pivot across data relationships to identify malicious activity, track malware families, inspect phishing infrastructure, and build statistics on threat actor activity. This process is intended to help uncover attacker patterns and analyze their behavior over time.