Home/Solutions/Threat Hunting
Capability · Threat Hunting

Hunt across every event, tagged to MITRE ATT&CK.

The signal is almost always already in your logs. Finding it should not require a query language and a free afternoon. Suriq retains your detections and events and makes them searchable by host, rule, severity, and source - and tags every detection with its MITRE ATT&CK tactic and technique, so a single odd event becomes a thread you can pull on.

The evidence is there. Getting to it is the hard part.

Hunting a threat usually means stitching together raw logs across hosts in a query language you half remember, before the data ages out of the index. The work is so heavy that most teams only do it after an incident, never before.

01

Every event, searchable

Detections and logs are retained and searchable by host, rule, severity, category, and source - filtered in plain terms, with no SPL or KQL to learn.

02

Tagged to the playbook

Every detection carries its MITRE ATT&CK tactic and technique, so you can pivot from a single signal to the wider pattern instead of guessing what it belongs to.

03

From signal to incident

Related events are correlated and deduplicated into incidents, with Jack a question away to explain what you are looking at and what to check next.

04

Turn a hunt into a rule

Found a pattern worth watching for? Because the engine is programmable Wazuh, you can codify a hunt into your own detection rule. Managed and community rule packs cover the common ground; your own rules cover what is specific to you.

Legacy stack vs. Suriq

DimensionLegacySuriq
SearchSPL / KQL requiredPlain filters
FramingRaw eventsMITRE-tagged
PivotManual joinsCorrelated into incidents

Frequently asked questions

Do I need a query language like SPL or KQL to hunt in Suriq?

No. Your detections and logs are retained and searchable with plain filters - by host, rule, severity, category, source, IP, user, or free text - so you hunt by narrowing a form, not by writing SPL or KQL. Read the exact matching events in seconds.

What can I hunt across?

Your detections and events are retained and searchable on a dedicated backend, so a hunt is not racing the data out of a hot index. Filter across every host and rule, pivot from one signal to the related activity, and keep old events ready to action instead of ageing out.

How does MITRE ATT&CK tagging help a hunt?

Every detection carries its MITRE ATT&CK tactic and technique, so a single odd event becomes a thread you can pull on. You pivot from one signal to the wider pattern instead of guessing what it belongs to.

Can I turn a hunt into a detection rule?

Yes. Because the engine is programmable Wazuh, you can codify a pattern you found into your own detection rule that runs going forward. Managed and community rule packs cover the common ground; your own rules cover what is specific to you.

Are related events grouped into one incident?

Yes. Related detections are correlated and deduplicated into a single incident with the evidence attached, and the AI interpreter can explain what you are looking at and what to check next. It advises; you decide what to do.

Ready to meet the Guardians?

Deploys fast - agentless for monitoring and cloud, a lightweight agent for deep endpoint security. Just Suriq, standing watch.