Hypotheses, queries and the ugly telemetry they match

A hunt starts with a hunch about something rude. If the model will not talk about that behaviour, it cannot help you write the query that would show it.

Hunters in SOCs and detection teams with access to the telemetry they are querying.

Why the mainstream APIs fail here

You ask for a hunt around LSASS access and get a refusal. You already have the EDR. You need the hypothesis and the query, not a reminder that dumping credentials is bad.

How Redline is used for this

Describe the hunch. Get the behaviour, the query, the false-positive shape. Run the query in your own tools. Cap the hunter key so a week of Playground use is a known number.

A working loop

  1. Start from a hunch or a report, not from a blank page.
  2. Generate the query for the tool you actually have.
  3. Record what you ran in the hunt log, not in Redline.

Prompts are not stored. A signed receipt of the hash comes back on every call, so you can prove later what Redline logged. Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.

Related