Workspace
Where a gap becomes your detection.
Write a detection in the language your engine reads, or start from a published one. Every save is a version you can go back to, a second person reviews it, and you decide who sees it.
- Start from a published ruleA rule from the catalogue, or a blank page.
- Save it: every save is a versionEach with the fingerprint of its content.
- Ask for a reviewA second person approves it.
- Share itYour workspace, people you name, or, once it is contributed, anyone with the link.
- Contribute itBack to the public catalogue, when it is ready.
The gaps
Start where nothing is published yet.
These are ATT&CK techniques with no published rule of their own, counted over the catalogue as it is right now.
What you can do
Everything a workspace holds.
- Your own rulesFree account
- Write a detection in the language your engine reads, or start from a published one.
- VersionsFree account
- Every save is a version that does not change, with the fingerprint of its content.
- ReviewFree account
- Ask for a review; a second person approves or rejects it. Nobody approves their own.
- Private sharingFree account
- Share a version with your workspace, with named people, or, once contributed, with anyone who has the link.
- ContributeFree account
- Submit a version to the public catalogue, and withdraw or resubmit it.
- Your teamFree account
- Team workspaces, invitations by email and a role for each member.
- Public profileFree account
- A handle and a public page with your contributions, if you choose to have one.
- Your accountFree account
- See and end your sessions, and delete your account.
Works with
Where the other two lead.
Not included
What it does not do yet.
- Comparing two versions of your own rule
- Mapping your own rules to ATT&CK
- Deploying to a SIEM or syncing with Git
- Testing a rule against your data
Start with what exists. Write what is missing.
The catalogue needs nothing from you. A workspace is free, and it is yours.