Threat Intelligence
Detection Rules
Manage SIGMA and YARA rules, or write your own.
Available as a standalone module · Add to my package18,406Active IOCs
57Matches today
212Techniques covered
- SigmaHQ rule importActive
- YARA signature libraryActive
- Custom rulesActive
- Suppressions and tuningActive
What it does
Browse, enable and tune the SIGMA and YARA rule sets, add custom rules, and suppress noisy detections without losing visibility.
SigmaHQ rule import
YARA signature library
Custom rules
Suppressions and tuning
How it worksin three steps.
Ingest
Open and commercial feeds refresh on a schedule.
Match
Every IP, domain, URL and hash in your events is checked.
Prioritise
Matches raise risk scores and open incidents where it matters.
Works best withthese modules.
See all 30 modules
Detection & Response
Incident Management
Correlated incidents with severity, assets and timeline.
Learn more Detection & ResponseThreat Hunting
Hypothesis-driven hunts across all your telemetry.
Learn more Endpoint SecurityVulnerability Management
Installed software matched against known CVEs.
Learn moreAlso in Threat Intelligence
Ready to see it on your own data?
A 30-minute walkthrough with an engineer, tailored to your environment.