← All Netgraph solutions
Threat Hunting & NQL Data SearchIntelligence & Operations

One query language. Every tier. Hunts that become detections.

NQL is Netgraph's platform-native query language, and it is everywhere users query data — Data Search across hot, warm and cold tiers, Discover, hunts and detection preview. It is auto-synthesized from natural language and auto-validated as you type, so the hypothesis in your head becomes a running query in seconds — and a hunt that confirms becomes a detection through the workbench.

NQL everywhereHot / warm / cold searchNL → NQL, validated on-typeScheduled hunt jobsGraph & blast-radius pivotingKQL / SPL / AQL federation

What ships in the module

Hypothesis to verdict, on one substrate.

01

NQL Data Search

Interactive search across hot, warm and cold tiers in one language — the same NQL that powers Discover, detection preview and hunts, with on-type validation in the shared editor.

02

Natural language → NQL

Describe what you want; the assistant synthesizes the NQL and validates it before it runs. Junior analysts hunt like seniors; seniors skip the syntax tax.

03

Hypothesis-driven hunts

Hypothesis → time-filtered NQL query → findings → escalate to a case or draft a detection. The hunt is a structured workflow with an outcome, not a scratchpad that evaporates.

04

Scheduled hunts

Cron-scheduled hunts with run-now, full run history and last-run result popups — the Hunt Run Jobs tab tracks every execution so recurring hunts are auditable, not folklore.

05

Entity Graph exploration

An interactive, cytoscape-class graph of entities and their relationships — pivot from a user to their hosts to their peers visually, and see why things are connected.

06

Blast Radius analysis

Start from a compromised entity and walk outward — what it touches, what trusts it, where an attacker goes next. Scoping a hunt becomes a traversal, not a spreadsheet.

07

Graph-grounded hunt agents

The Threat Hunter and Hunt agents run read-only hunts over the same substrate you use — same NQL, same graph, same evidence. Agent findings are reproducible because you can rerun the query.

08

External SIEM federation

Where SIEM integrations are enabled, queries forward to external KQL, SPL and AQL dialect targets — hunt across the estate you have, not just the data you've migrated.

09

Detection flywheel

Hunts that confirm become detections through the workbench — compiled, backtested and deployed in the same NQL. Yesterday's hunt is tomorrow's automated coverage.

The hunt loop

Hypothesis in. Case or detection out.

Every hunt in Netgraph follows the same closed loop: state a hypothesis, express it as a time-filtered NQL query, read the findings, then escalate — open a case for what's live, or draft a detection so the technique never needs hunting again. Scheduled hunts keep the loop running while you sleep.

  • Time filters are explicit: ingest_time > now() - INTERVAL N HOUR scopes every hunt.
  • Run-now for iteration; cron for recurrence; run history and last-run popups for accountability.
  • Pivot mid-hunt through the Entity Graph and Blast Radius without leaving the investigation.
  • Confirmed hunts graduate to the Detection Workbench — compile, backtest, deploy.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Data SearchInteractive NQL search across hot / warm / cold tiers with on-type validationVisibility ▸ Data Search
DiscoverExploratory analytics over the same data in the same NQLAnalytics ▸ Discover
Hypothesis huntsHypothesis → time-filtered NQL → findings → case or draft detectionScheduled hunts pages
Hunt Run JobsCron scheduling, run-now, run history, last-run result popupsScheduled hunts ▸ Run Jobs
Entity GraphInteractive graph exploration of entities and relationshipsVisibility ▸ Entity Graph
Blast RadiusOutward traversal from a compromised entity for scoping and pivotingAnalytics ▸ Blast Radius
Hunt agentsThreat Hunter / Hunt agents run read-only hunts over the same substrateAgentic SOC
SIEM federationForward queries to KQL / SPL / AQL targets where integrations are enabledNQL federation layer

See it live

Bring your best hypothesis. Leave with a detection.