The Threat Hunting Platform by Hunt Intelligence is a SaaS-based intelligence solution designed for security teams to map and analyze adversary infrastructure. It utilizes continuous internet scanning to discover and track malicious activity, including active command and control (C2) servers and payload hosts. The platform consolidates infrastructure-level intelligence and indicators of compromise linked to threat actors, enabling personnel to conduct investigations and correlate data in real-time within a unified interface without exporting data.
Technical capabilities include the scanning and analysis of open ports, custom C2 protocols, JARM hashes, SSH keys, and parsed SSL/TLS certificates. It provides specific functions for investigating exposed open directories to find misconfigured servers or malware. The system features visual analysis tools, bulk enrichment to extract indicators from unstructured text, and consolidated historical IP data across ASNs and geolocations. Infrastructure tracking incorporates JA4+ fingerprinting and deep TLS certificate visibility. Enterprise single sign-on (SSO) is supported via SAML 2.0.