Skip to content
← The Huntr family

Database activity monitoring

Huntr for Database

Know who touched your data.
Keep the evidence.

Build a searchable audit trail from Oracle and SQL Server native audit output. Give database, security and audit teams the identity, activity and source context they need.

HUNTR DATABASE
Oracle auditSQL Server auditIdentitySource context
H
One connected viewDatabase activity monitoring
  1. 01Native audit
  2. 02Retain records
  3. 03Attribute activity
  4. 04Export evidence

Capability overview

Built for the work ahead

Context you can use.
Control you can act on.

01

Collect audit evidence off-box

Consume the database’s own audit output outside the SQL execution path. Start with the audit configuration and source coverage required for your environment.

02

Answer who, what, when and where

Review authenticated identities, recorded actions, timestamps and source context. Follow access history through a queryable record instead of piecing together disconnected exports.

03

Retain and retrieve the trail

Keep audit records in a secured, searchable store with a defined retention policy. Find the events relevant to an investigation or review without losing their source context.

04

Build reporting around audit needs

Use scheduled reports and evidence export to support reviews. Enable detection content when monitoring requirements expand beyond the audit-first profile.

Where it helps

Start with a real problem.

Review privileged activity

Examine administrative access and recorded changes, with identity and source details available for follow-up.

Prepare an audit evidence package

Retrieve the relevant records for a period or identity and export evidence for the people conducting the review.

Investigate unexpected data access

Trace recorded activity back to the account and source, then coordinate follow-up with the database and security owners.

An example workflow

An unexpected privileged account action

Explore each step. Response actions are configured around your integrations, permissions and operating procedures.

Step 1 of 4

Record

Ingest the action from the database’s configured native audit output.

Your environment. Your boundaries.

Deployment that fits.

Keep the data plane dedicated to your organization, deploy within your own environment or use an air-gapped profile. Plan native audit settings, storage retention, access permissions and reporting before rollout.

  • Dedicated environment
  • On-premises
  • Air-gapped

Before you begin

A few useful answers.

Does Huntr sit in the SQL execution path?

No. This edition consumes native audit output off-box. It is designed around retained evidence and attribution, rather than intercepting every SQL statement.

Is detection enabled by default?

The database edition is audit-first. Detection is available but off by default in its documented profile; it can be enabled when broader monitoring is needed.

Does it replace database access controls?

No. Identity and database layers remain responsible for access enforcement. Huntr supplies activity visibility, evidence and optional detection to support investigation and coordinated response.

Huntr for Database

Bring your environment.
Let’s work through the response.

Show us your sources, investigation needs and operating procedures. We’ll discuss the right scope and walk through a relevant workflow.