Qingteng Falcon Threat Hunting Platform by Qingteng helps users address issues such as security data aggregation, data mining, event tracing, and security capability integration. Based on the ATT&CK framework, it provides hundreds of ATT&CK attack scenarios for deep data mining and utilizes Qingteng's self-developed QSL language to track abnormal activities and timely identify potential threats. The core architecture consists of data collection, data analysis, and a web console, connecting multiple data sources for linked analysis based on the ATT&CK framework. It deeply integrates with Wanxiang products, incorporating over 50 types of raw data covering assets, risks, intrusions, logs, tasks, and all Wanxiang functions. It also supports connections to custom data sources like ElasticSearch, MongoDB, MySQL, etc. The data analysis utilizes Qingteng's self-developed SQL-like query engine—QSL, supporting common SQL query syntax and allowing for data joint queries. The web console includes a dashboard displaying commonly used queries or command lists, allowing users to quickly access data for analysis. Categories include security events, asset overview, ATT&CK, threat capture, and security response, with support for API, file, and chart exports. Qingteng Falcon provides detection methods for over a hundred attack techniques through in-depth research of all attack tactics and techniques, allowing for comprehensive query analysis to deeply mine server event data, merging data across dimensions to detect security threats promptly. It includes a machine learning engine based on User Entity Behavior Analysis (UEBA) for anomaly detection, clustering, and association analysis, as well as an anomaly login detection model to quickly and effectively identify abnormal behavior. It offers unified analysis of heterogeneous data, addressing the limitations of single product capabilities.