Active & continuous search
Monitoring built on searching directly for markers on systems — the ability to verify a presence, rather than infer it from a log stream.
HUNTRY actively hunts indicators of compromise directly on your systems — instead of waiting for an alert to fire.
Traditional mechanisms (EDR, SOC, IDS) react to alerts generated by static rules. Threat hunting takes a dynamic, targeted approach: searching for the traces — the artifacts — left behind by attackers.
Overwhelmed by alerts generated by static rules, operations centres miss what matters. HUNTRY doesn't replace the SOC — it closes its blind spot.
HUNTRY deploys a gateway inside your perimeter: it searches for markers directly on your systems, then talks to the HUNTRY platform over an encrypted VPN tunnel. Your systems are never exposed — an architecture aligned with ANSSI frameworks.
Client side — the gateway lives in your network, as close as possible to your systems.
Encrypted VPN tunnel — the only link to the HUNTRY platform, controlled and one-way.
HUNTRY side — detection engine and IoC database, isolated from your systems.
Every marker follows the same path: collected from multiple sources, sorted then pruned, consolidated in our database, and checked in real time against your monitored systems.
A technical trace left by an intrusion. HUNTRY verifies its presence where it counts — directly on the machine.
HUNTRY's innovation rests on four pillars — from approach to architecture.
Autonome — ou intégré à votre stack existante.
Monitoring built on searching directly for markers on systems — the ability to verify a presence, rather than infer it from a log stream.
HUNTRY relies on open-source tools not exclusively dedicated to hunting. A choice in favour of transparency, trust and reusability.
Beyond external sources: honeypots, malware analysis in a sandbox, vulnerability intelligence and lessons from WELAN's incident-response engagements.
Designed to ANSSI frameworks, the architecture deploys an "enclave" on the client side — guaranteeing isolation, even if an incident hits HUNTRY's own infrastructure.
HUNTRY draws on WELAN's expertise in threat detection, built over real-world engagements.
SOC audits — assessing detection capabilities under real conditions.
SIEM integration in-house, and industrialising collection.
Detection strategies tailored to the monitored environments.
David Weber, president of WELAN, is a PDIS assessor qualified by ANSSI. This expertise — at the heart of the French state's detection frameworks — feeds directly into HUNTRY's methodology.
See how HUNTRY continuously checks your perimeter against a living database of markers — and reveals what static rules let through.