Easy threat hunting with Trunc. You can deep dive into all your logging data - from all your servers and products to identify suspicious activities. With our Security Insights, you can quickly identify areas to investigate.
Supports all server distributions (i.e., Windows, Linux, etc). Agent-less and Encrypted agent options available.
Over the years, we have supported numerous organizations in identifying and mitigating security breaches. Many of those compromises were not uncovered by a formal detection mechanism. They were found by what we might call serendipitous discovery: during a routine investigation, an analyst noticed something irregular and unrelated to the original question, and pulling on that thread led somewhere nobody expected.
"While investigating A, I encountered B, which was out of place, leading me to uncover C, clear evidence of a security compromise."
In other cases the organization is not the first to know. The notification comes from law enforcement, a threat intelligence partner, a customer, or the attackers themselves through a ransomware demand. This happens at companies with substantial security budgets and current tooling, which is the uncomfortable part: the technology was present and the intrusion still went unnoticed for months.
The reason is usually the same. Detection rules catch what somebody already characterized, and an attacker who is careful, or who is using valid credentials they stole, produces little that any rule was written for. A successful login is not an alert. Neither is a file being read, or a DNS lookup, or an outbound connection on port 443. Everything an attacker does after the first step tends to look like ordinary activity, because ordinary activity is what they are imitating.
To stay ahead of that, we advocate for a proactive practice known as exploratory threat hunting, or just threat hunting. It means setting aside regular time, daily or weekly, to start with no alert and no assumption, and go looking for anomalies, unusual patterns and subtle indicators of compromise.
A hunt is a question, a search that answers it, and a decision about what you found. Most hunts find nothing, and that is a normal result: you have ruled out a scenario. The ones that find something usually start from a hypothesis specific enough to be wrong.
A few that are worth an hour of anybody's week:
Every one of those needs the logs nobody flagged. That is the part worth noticing: tools built purely for detection discard the events where nothing matched a rule, and those are precisely the events a hunt searches through.
Hunting is iterative. You run a search, look at what came back, narrow it, and run it again. If each round trip is slow you stop after four attempts, and the answer was going to be on the seventh. Everything below exists to keep you moving.
Real time search across everything
Full text search over every log you have sent, with field filters for host, category, country, date and time. Results come back while you are still looking at the screen, and every log is kept rather than only the ones that triggered something. Search a source address and see everything it has ever done across your entire estate, whichever device recorded it.
Security Insights, so you know where to start
The hardest part of a hunt is choosing where to look. Security Insights runs a standing set of checks across your logs and reports what needs attention, what is worth reviewing, and what came back clean. Brute force attempts, successful attacks, scanning activity, web attacks, access denials and reputation matches, each with the sources and counts behind them and a search waiting one click away.
Operational Insights, where the odd things surface
Not every finding is a security event, and some of the most useful leads are operational. Sources that stopped reporting. Hosts whose volume changed. Errors that started appearing after a deployment nobody mentioned. This is where the "that is strange" moments come from, and those moments are how serendipitous discovery happens on purpose.
Charts that show shape, not just totals
Volume over time split by severity, category breakdowns, top talkers and geographic distribution. The value is not the number, it is the silhouette: a plateau where there was a slope, a spike at three in the morning, a country appearing that was never there before. Your eye catches those far faster than a query does, and then you use the query to confirm.
Categories across every source
Every event is tagged with what it means as well as what it says, so you can ask for all authentication failures on the estate without knowing which firewall, server or application produced them, or what their log formats look like. That is what makes a hunt that spans twelve different log sources a single search instead of twelve.
Correlation already running
Some of the patterns above do not need hunting because Trunc watches for them continuously. Repeated failures followed by a success. Scanning across your web servers. A source that has gone silent. They are flagged when they happen, which frees your hunting time for the questions nobody has automated yet.
Retention that reaches back
Dwell time between compromise and discovery is routinely measured in months. Thirty days of logs means you cannot answer a question about anything that started in the spring, and the question you most want to answer after finding something is how long it has been going on.
An hour a week beats a day a quarter. Hunting depends on knowing what normal looks like in your own environment, and that only comes from looking at it often. A short regular session builds the instinct, and the instinct is what makes the difference on the day something is wrong.
Keep notes on what you searched and what you found, including the hunts that found nothing. Six months later the value is in knowing what you already ruled out.
And when a hunt finds the same thing twice, turn it into an alert. The point is not to keep hunting for something you now know how to detect.
14 days free trial. No credit card required.