Collect audit evidence off-box
Consume the database’s own audit output outside the SQL execution path. Start with the audit configuration and source coverage required for your environment.
Database activity monitoring
Huntr for Database
Build a searchable audit trail from Oracle and SQL Server native audit output. Give database, security and audit teams the identity, activity and source context they need.
Capability overview
Built for the work ahead
Consume the database’s own audit output outside the SQL execution path. Start with the audit configuration and source coverage required for your environment.
Review authenticated identities, recorded actions, timestamps and source context. Follow access history through a queryable record instead of piecing together disconnected exports.
Keep audit records in a secured, searchable store with a defined retention policy. Find the events relevant to an investigation or review without losing their source context.
Use scheduled reports and evidence export to support reviews. Enable detection content when monitoring requirements expand beyond the audit-first profile.
Where it helps
Examine administrative access and recorded changes, with identity and source details available for follow-up.
Retrieve the relevant records for a period or identity and export evidence for the people conducting the review.
Trace recorded activity back to the account and source, then coordinate follow-up with the database and security owners.
An example workflow
Explore each step. Response actions are configured around your integrations, permissions and operating procedures.
Step 1 of 4
Ingest the action from the database’s configured native audit output.
Your environment. Your boundaries.
Keep the data plane dedicated to your organization, deploy within your own environment or use an air-gapped profile. Plan native audit settings, storage retention, access permissions and reporting before rollout.
Before you begin
No. This edition consumes native audit output off-box. It is designed around retained evidence and attribution, rather than intercepting every SQL statement.
The database edition is audit-first. Detection is available but off by default in its documented profile; it can be enabled when broader monitoring is needed.
No. Identity and database layers remain responsible for access enforcement. Huntr supplies activity visibility, evidence and optional detection to support investigation and coordinated response.
Huntr for Database
Show us your sources, investigation needs and operating procedures. We’ll discuss the right scope and walk through a relevant workflow.