> For the complete documentation index, see [llms.txt](https://docs.inopli.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.inopli.com/drp/hunt/search-results.md).

# Search Results

Once a <mark style="color:green;">hunt query</mark> is executed, the <mark style="color:green;">**Results**</mark> page displays all matched threat intelligence entries based on the selected indicator and search term. The returned findings are enriched with metadata to support prioritization and further investigation.

Each result represents a correlated threat signal found within the Inopli DRP database or across integrated external sources. The system aggregates and categorizes findings to streamline triage and decision-making.

***

### Result Summary Overview

At the top of the Results screen, summary indicators are displayed:

* <mark style="color:green;">**Total Results**</mark> – Total number of matching threat records
* <mark style="color:green;">**Search Time**</mark> – Time taken to complete the query (in milliseconds)
* <mark style="color:green;">**Search Term**</mark> – The query string used during the hunt

***

### Result Table Fields

Each result row contains:

* <mark style="color:green;">**ID**</mark> – Unique incremental identifier for visual sorting
* <mark style="color:green;">**Category**</mark> – General threat category (e.g., Malware, Phishing, InfoStealer)
* <mark style="color:green;">**Type**</mark> – Specific sub-type within the category (e.g., Ransomware, Email, Domain)
* <mark style="color:green;">**Values**</mark> – IOC(s) matched against the hunt query (e.g., domain, email, hash)
* <mark style="color:green;">**Confidence**</mark> – Estimated confidence level (e.g., 85%) based on correlation signals and source reliability
* <mark style="color:green;">**UUID**</mark> – Internal unique identifier for traceability and pivoting
* <mark style="color:green;">**Threat Data**</mark> – Origin scope of the intelligence (e.g., Global, Regional, Tenant-based)

Each result can be expanded or clicked to view full details, including the source, enrichment layers, relationship graph, and timestamps.

<figure><img src="https://2621223932-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FLTQJomzpe5BTzHSLQPAt%2Fuploads%2FYWyv5SQhZlYDJWIlbfw4%2Fimage.png?alt=media&amp;token=df8e1559-70db-4183-8fbd-0b503e4481d4" alt=""><figcaption></figcaption></figure>

All search results can be <mark style="color:green;">**exported**</mark> in multiple formats to support external analysis, reporting, or archival. Supported formats include <mark style="color:green;">**CSV**</mark> for structured data handling, <mark style="color:green;">**PDF**</mark> for static reporting, and <mark style="color:green;">**HTML**</mark> for easy sharing or offline review. Exports preserve metadata such as confidence level, threat category, and UUID for traceability.
