Sophia
Hart

Hexnode XDR Investigate Tab: A Walkthrough of the Threat-Hunting Query Builder

Sophia Hart

Oct 8, 2026

9 min read

hexnode xdr investigate tab

TL; DR

  • The Hexnode XDR Investigate Tab helps analysts query endpoint telemetry to investigate suspicious activity and establish its scope.
  • Unclear scope can delay containment, increase manual checks, and complicate analyst handoffs.
  • Define a time window, build search conditions, and assess matches in context using platform-appropriate telemetry.
  • Save and share query logic and export findings to support repeatable investigations.

How do you investigate suspicious activity beyond an alert?

To investigate suspicious activity beyond an alert, examine endpoint telemetry to establish what happened, which user was involved, and whether related activity appears on other devices. The Hexnode XDR Investigate Tab provides a workspace for searching and analyzing that activity.

An alert gives analysts a starting point, but an isolated event may leave important questions unanswered. Does the process belong to an approved application? Does the same activity appear elsewhere? These questions shape the investigation.

This walkthrough shows security teams how to build threat-hunting queries, interpret matching events, and save searches for reuse when investigating Windows and macOS endpoints.

What happens when analysts cannot establish an incident’s scope?

Uncertainty about affected endpoints can delay containment decisions or lead analysts to investigate unrelated activity. Without a clear scope, teams struggle to prioritize follow-up work and explain which systems require attention.

  • Repeated manual checks: Analysts revisit endpoint activity and repeat searches to determine whether individual events belong to the same incident.
  • Incomplete handoffs: Missing details about affected devices and unresolved questions force the next analyst to retrace earlier work.
  • Unclear findings: Security teams struggle to explain what the evidence establishes, where uncertainty remains, and why they recommend a particular response.

What is the Hexnode XDR Investigate Tab?

The Hexnode XDR Investigate Tab lets analysts query endpoint telemetry to examine activity, identify suspicious patterns, and locate relevant endpoints. Analysts build search conditions using a field, comparator, and value, such as matching a process name to investigate where an executable appeared.

Query results provide evidence, but a match alone does not confirm a threat. Analysts must assess its context before concluding. Investigate supports telemetry analysis, while the Incidents tab provides incident details, technician assignments, and status tracking to support incident response.

Which telemetry matters for Windows and macOS Investigations?

The Hexnode XDR agent supplies telemetry from monitored Windows and macOS endpoints. Process, file, network, and endpoint data provide useful context for investigations.

Depending on the platform and available telemetry, examine:

  • Process execution: Executable activity and associated process details.
  • File activity: Recorded creation, modification, or access events.
  • Network behavior: Connections, IP communications, and DNS activity.
  • Endpoint context: Hostnames, operating system details, and device identifiers.

For Windows and macOS investigations, use available telemetry and platform-appropriate executable names and paths. Verify field and event availability before applying the same query across both operating systems.

How do you build a threat-hunting query in Hexnode XDR?

To build a threat-hunting query in the Hexnode XDR Investigate Tab, establish the investigation scope, construct search conditions, run the query, and interpret the evidence. Follow these steps to move from an initial question to a reusable search.

Step 1: Define the investigation question and time window

Start with a specific question: Has the process under investigation appeared on additional endpoints? Record the originating endpoint, the observed process, and the reason for investigating it.

Open Investigate and set the Time Range around the activity under review. Use the known event timestamp as a starting point, allowing enough context to examine relevant activity before and after it.

Confirm that relevant endpoints have the XDR agent and review their connectivity status. Current connectivity alone does not establish whether telemetry exists for the earlier investigation period.

Step 2: Build the first search condition

Click inside the search bar and select a field from the available suggestions. Choose a comparator to define how the field should match:

  • Equal to / Not equal to: Match a complete value or exclude that value.
  • Contains / Does not contain: Include or exclude values containing the specified text.
  • Begins with / Ends with: Match the beginning or end of a value.
  • Is empty / Is not empty: Check whether the field contains a value.

For a value-based condition, enter information observed during the investigation. Use Equal to when you know the complete value. Use partial matching when you need to find values sharing a relevant text pattern, while accounting for unrelated matches.

The completed condition appears as a query bubble. You can edit or delete individual bubbles as you refine the search. Check that each field and value applies to the endpoint activity you intend to investigate.

Step 3: Combine conditions and run the query

Connect conditions using AND or OR. AND requires an event to satisfy all connected conditions. OR includes events that satisfy any connected condition.

Investigation goal Conditions to combine Expected matching behavior
Find a particular process on one endpoint Process condition AND endpoint condition Each matching event satisfies both requirements.
Search for either of two executable names First process condition OR second process condition Each matching event satisfies at least one process condition.

These examples describe the intended logic; select the corresponding fields and values through the query builder.

Review the conditions before selecting Run Query. An additional AND condition can exclude relevant events when it requires a value they do not contain. Keep each condition tied to the investigation question.

Step 4: Interpret and export the results

Review the matching records in the results table beneath the search bar. Use the available columns to understand each event:

  • Time: When the recorded event occurred.
  • Event: The type of activity.
  • Endpoint: The device where it occurred.
  • Username: The user account associated with the event.
  • Process Name: The executable involved.
  • Attributes: Event-specific details, such as process identifiers, executable paths, or parent processes, where available.

A match shows that an event satisfies your conditions. Assess the activity’s purpose and surrounding evidence before recommending escalation. For example, an executable’s presence may warrant further investigation, but its name alone does not establish malicious behavior.

Select Export to download the results in CSV, XLSX, or PDF for further analysis or evidence sharing.

Step 5: Save, reuse, and share the investigation logic

Once you have built the query, open Actions > Save Query. Give it a descriptive name and use the optional description to record its purpose, relevant assumptions, and investigation reference.

To reuse it, open Saved Queries and select Add to load its conditions into the search bar. Recent Searches also lets you revisit previously executed queries for further refinement.

Use Share Query to export the query structure for documentation or analyst handoffs. Use Export when you need the matching event results.

Before reusing a search, reassess its values and time window. Investigation notes should help the next analyst understand which assumptions still apply and which conditions need adjustment.

How do you extend an investigation across endpoints?

Extend an investigation by using the initial observation to search for related activity on other endpoints. In Hexnode XDR, start with a process value from the existing investigation and follow the evidence through additional questions:

  • Does the process appear elsewhere? Broaden the search beyond the original endpoint while retaining the relevant process condition.
  • When did the activity occur? Compare timestamps to understand whether the observations overlap or recur.
  • Does the context match? Examine associated users and available executable paths or parent-process details before linking events.

Document the observed activity, relevant endpoints, remaining uncertainty, and next investigative question. Treat a matching filename as a lead that requires context before connecting it to the same incident.

How do you troubleshoot empty or overly broad query results?

Review the time window, field values, comparators, and logical operators to identify why a query returns insufficient or irrelevant results.

Query problem What to check Suggested adjustment
Empty results Spelling and capitalization Correct typos and match the recorded capitalization. Queries are case-sensitive.
Expected activity is missing Selected time window Adjust the range to include the activity under investigation.
Too few matches Restrictive AND conditions Revise conditions that unnecessarily exclude relevant events.
Too many unrelated matches Broad OR conditions or partial matching Use more specific values, exact matching, or AND when every condition must apply.

Hexnode documents case sensitivity, time-range checks, and careful use of logical operators as query considerations.

Change one condition at a time, then select Run Query to assess its effect. Zero matches reflect the selected conditions, time window, and available telemetry. They do not establish that an endpoint is free from compromise.

How does Hexnode support repeatable threat-hunting workflows?

The Hexnode XDR Investigate Tab supports repeatable threat hunting by helping analysts construct searches, revisit earlier work, and share investigation logic.

  • Intuitive Query Builder: Search suggestions, recent history, and saved queries help analysts refine existing searches as investigation questions evolve.
  • Efficient Query Workflow: Building, saving, and sharing queries helps teams preserve their search logic for recurring checks and analyst handoffs.
  • Actionable Data Tables: Structured results help analysts review matching events and export findings for further analysis or evidence sharing.

Evaluate these capabilities using a known observation from your Windows and macOS environment, after confirming the available telemetry for each platform. Can your team investigate the observation, explain what the results establish, and give another analyst enough context to continue the work?

introduction to hexnode xdr
Featured resource

Introduction to Hexnode XDR

Explore how Hexnode XDR unifies threat visibility, investigation, and response while integrating with Hexnode UEM.

DOWNLOAD

FAQs

No, you can build queries by selecting fields, comparators, and values through the interface. Combine conditions with AND or OR to define which events the search should return.

Reuse depends on whether the query’s fields and conditions apply to the target platform’s available telemetry. Check event coverage, executable names, and paths before applying the query to another operating system.

A saved query preserves search logic, while its results depend on the selected time window and available telemetry. Before comparing two runs, check that their conditions and time windows match, and account for differences in the available records.

Put the Hexnode XDR Investigate Tab into your investigation workflow

Start with one investigation question drawn from your organization’s endpoint activity. Test the search conditions, review the evidence, and identify what you still need to establish. Use the exercise to assess how the Investigate tab fits your team’s approach to threat hunting.

Bring that question to a guided walkthrough. Request a Hexnode XDR demo to explore the Investigate tab using threat-hunting scenarios relevant to your Windows and macOS environment.

Share

Sophia Hart

A storyteller for practical people. Breaks down complicated topics into steps, trade-offs, and clear next actions—without the buzzword fog. Known to replace fluff with facts, sharpen the message, and keep things readable—politely.