Skip to content

THREAT HUNT

radar


RadarThreatHuntCancelled

${user} canceled the threat hunt '${huntName}' started on ${huntDate}.

SeverityStatusAudit Event
InfoSuccessYes

RadarThreatHuntCsvDownload

${user} started a CSV download of threat hunt '${huntName}' created on ${huntDate}.

SeverityStatusAudit Event
InfoSuccessYes

RadarThreatHuntStarted

${user} started an advanced threat hunt '${huntName}' on ${huntDate}.

SeverityStatusAudit Event
InfoSuccessYes

RadarTurboThreatHuntStarted

${user} started a fast turbo-charged threat hunt '${huntName}' on ${huntDate}.

SeverityStatusAudit Event
InfoSuccessYes

threat_hunt


ThreatHuntAborted

Threat hunt ${huntName} was aborted due to file match limit exceeded. Start a threat hunt with narrower IOCs or lower number of objects to have the file match count within the allowed limit.

SeverityStatusAudit Event
CriticalCanceledNo

ThreatHuntCanceled

Threat hunt ${huntName} was canceled.

SeverityStatusAudit Event
InfoCanceledNo

ThreatHuntFailed

Threat hunt ${huntName} failed to complete. Reason: ${reason}

SeverityStatusAudit Event
CriticalFailureNo

ThreatHuntInProgress

Started scanning the object snapshots.

SeverityStatusAudit Event
InfoRunningNo

ThreatHuntPartiallySucceeded

Threat hunt ${huntName} partially succeeded with ${objSucceeded}  objects successful, ${objPartiallySucceeded} objects partially  successful, and ${objFailed} objects failing. There were  ${objectMatches} object matches and ${fileMatches} file  matches.

SeverityStatusAudit Event
CriticalFailureNo

ThreatHuntStarted

${userEmail} initiated ${huntType} threat hunt: ${huntName}.

SeverityStatusAudit Event
InfoTaskSuccessNo

ThreatHuntSucceeded

Threat hunt ${huntName} completed successfully for all the objects.  There were ${objectMatches} object matches and ${fileMatches} file  matches.

SeverityStatusAudit Event
InfoSuccessNo