Skip to main content

Detections

The Detections tab (Intelligence › Detections) is the operational view of your organization's detection rules. It lists every rule your organization can run, with whether its tests pass, whether it can fire, how much it fires, how often it's right, and where it is in quarantine or rollout. Use it to test and measure rules. Use Watchers to switch rules on and off and tune them.

The rules themselves are templates in the Library. Browse them, enable one for your organization, customize one into your own rule or fetch SigmaHQ rules in Library › Detections. The link at the top of this tab takes you there.

Beta

Detections is part of Intelligence, which is in beta. Access is by request, so it may not be enabled for your organization.

The rules table​

Detections follows the organization selected in the scope selector. Under a personal scope the tab asks you to choose an organization.

ColumnWhat it shows
RuleThe rule's name, where it comes from (SigmaHQ, Hub, Custom for your own, or Huntbase) and its identifier.
BackingHow the rule is written (Sigma, Cypher or Builder) and the plane it runs on (Stream, Graph, Correlation or Intel).
ATT&CKThe techniques the rule detects. Select a technique to show only rules for it.
TestsPassed tests out of the total, No tests, or Error if the last run errored.
ReadinessWhether the rule can fire: Armed, Needs data (the data it needs isn't arriving) or Check unavailable. Hover for the detail.
ModeOn, Shadow or Off in this organization. Quarantined appears when the rule is being held in shadow because it fired far too often (see Quarantine). Promote appears when a shadow rule looks ready to switch on.
RolloutFor a rule going through automated rollout, the stage it's at, such as Shadow or Canary, plus the status when it isn't simply moving along (for example Blocked or Paused).
7d volumeHow many times the rule fired in the last 7 days. For a shadow rule, hover to see how much of that went to the daily digest.
PrecisionThe share of the rule's hunts that were confirmed rather than marked false positive over 90 days. It shows — until there are at least 3 verdicts.
Last firedWhen the rule last fired, or Never.

The list loads 50 rules at a time. Select Load more at the bottom for the next page.

Filters​

  • Search rules matches rule names and identifiers.
  • Source, Mode, Rollout, Tests and Plane narrow the list. Each option shows how many rules it matches. Mode › Quarantined lists the rules that are quarantined in this organization.
  • Noisy shows rules that fire a lot.
  • Not ready shows rules that can't fire because the data they need isn't arriving.
  • A technique you selected in the ATT&CK column shows as a chip. Select it to clear it.
  • Clear filters removes everything except the open rule.
  • Platform administrators also see an Unpublished switch next to the filters, which includes unpublished catalog rules in the table.

Filters are kept in the page address, so you can bookmark or share a filtered list. Other Intelligence tabs link here pre-filtered. For example, a threat's uncovered techniques open the rules for that technique.

A rule's details​

Select a rule's name to open its details. Open in Watchers takes you to the same rule on the Watchers page, where you switch it on or off and tune it. Template opens the rule in Library › Detections, where you can read its rule and customize it.

Overview​

  • Fires, fires in shadow and hunts opened over the last 30 days, with a daily bar chart. Lighter bars are days when every fire went to the digest.

  • Precision over 90 days, with the numbers of confirmed and false-positive verdicts behind it. Verdicts come from the hunts the rule opened.

  • Ready to promote to On when a shadow rule has been in shadow long enough, fires rarely enough, isn't imprecise and has no failing tests. Otherwise the reason it isn't ready yet. Promoting is still your decision: switch it to On from the rule's Tuning tab in Watchers.

  • If the rule is quarantined, a banner at the top explains why. See Quarantine.

Tests​

A rule's tests are example events it must match and events it must not match. Running them passes each event through the same matching logic the live rule uses, so a passing test means the rule really does fire on that event.

  • Run tests runs every test and records the run. The line above the tests shows the last run's result, the rule version it ran against and when.
  • Each test shows Pass, or Fail with what happened instead (matched or did not match), or Error with the reason. Expand Event to see the test's event.
  • For your own (Custom) rules, Edit tests lets you add, change and remove tests, then Save tests. Each test needs a unique name, an expectation, and an event written as a JSON object of field names and values. Surface is optional and names the data type the event belongs to, such as hb_process_activity.
  • Tests for Huntbase and SigmaHQ rules are read-only.
tip

Give every rule at least one must-not-match test. It's what catches a rule that fires on everything.

Backtest​

Runs the rule over your telemetry for the last 1, 7, 14 or 30 days without switching anything on. You get two numbers:

  • HKQL count is fast, but only approximates regular expressions and IP ranges.
  • Exact predicate (estimated) runs the live matching logic over a sample of your data and scales it up. The line under it says how many sampled rows matched.

When the two diverge, the page says which one is higher. Expect live volume to be closer to the exact estimate. Sample matches are listed underneath.

Only stream rules can be backtested. Graph, correlation and intel rules run over live state, so there's no history to replay.

Convert​

Translates a Sigma rule into a SIEM query language, for data that stays in your SIEM:

TargetLanguage
SplunkSPL
Microsoft Sentinel / DefenderKQL
ElasticES|QL
QRadarAQL (coming soon)

Choose the target and select Convert. Copy the query, and read any warnings shown under it. If the rule uses something the target can't express, the page names it instead of showing a query. If your organization has a connection that runs that language, Open in Explorer opens the query in a new Explorer tab against that connection. Nothing runs until you run it.

Only Sigma rules can be converted.

Rollout​

The Rollout tab shows where a rule is in its automated rollout. See Quarantine and rollout.

SigmaHQ rules​

SigmaHQ rules are never shipped by Huntbase. An organization admin fetches them into the organization, after accepting the Detection Rule License (DRL) 1.1, from the SigmaHQ rules card in Library › Detections. Fetched rules show here with source SigmaHQ.

Next steps​