Skip to main content

Detections

Library › Detections is the catalog of detection templates your organization can use. A template is a detection rule you can switch on for your organization as it is, or copy and change into a rule of your own. The catalog holds:

  • Huntbase rules: the SIGMA and graph detections Huntbase writes and maintains;
  • SigmaHQ rules your organization fetched (see SigmaHQ rules);
  • rules your org wrote, or customized from a template.

Rules that are off are listed too. This is what your organization could run. What it does run, and how each rule performs, is in Intelligence › Detections. Every template links to its operational view there, and every rule there links back to its template here.

Beta

Detections is part of Intelligence, which is in beta. Access is by request, so it may not be enabled for your organization. It follows the organization selected in the scope selector. Under a personal scope it asks you to choose an organization.

Browse detections​

Open Library and select Detections in the facet rail. Each template shows as a card, or a row in list view, with:

ElementWhat it shows
KindDetection · SIGMA, Detection · Graph or Detection · Intel
Severity and originThe rule's default severity, and Huntbase, SigmaHQ or Your org
ATT&CKUp to three technique IDs, with a +N overflow
ReadinessReady on your data, or Needs data when the data the rule reads isn't arriving in your organization. Hover for the detail.
TestsPassed tests out of the total, or No tests
Data sourceWhat the rule reads, such as Process activity, or Entity graph for a graph detection
In useShadow or On when your organization runs the rule, otherwise Not in use

The search box at the top matches rule names, identifiers and techniques. Use the filters to narrow the catalog. Every option shows how many templates it matches across the whole catalog.

FilterWhat it does
Tactic / TechniqueMITRE ATT&CK tactic or technique
Data sourceThe data the rule reads
OriginHuntbase, SigmaHQ or Your org
SeverityCritical, High, Medium, Low or Informational
ReadinessReady on your data or Needs data

Applied filters show as chips under the filters. Remove one from its chip, or select Clear all.

A template​

Select a card to open the template in a side panel. Full page opens it on its own page, with a link you can share. The template shows:

  • its description, origin, severity, the data it reads and whether it can fire on your data;
  • whether your organization uses it, in Shadow or On, and where it is in its rollout;
  • its ATT&CK techniques, each linking to MITRE ATT&CK;
  • the rule: the SIGMA for your own rules and SigmaHQ rules, or a description for graph and intel detections. The SIGMA source of Huntbase-authored rules isn't shown;
  • its tests and their last run. Run tests runs them now. You can edit the tests of your own rules.

Enable for my org​

Enable for my org switches the rule on for your organization in Shadow. It records its matches to the daily digest without notifying anyone or opening hunts, and never goes straight to On.

  • For your own rules and SigmaHQ rules, if automated rollout is on for your deployment, the rule also enters its rollout. The rollout promotes it from shadow once its tests, backtest and shadow period pass. See Rollout.
  • Otherwise, promote it yourself once you've seen it run: Intelligence › Detections shows a Promote hint when a shadow rule looks ready, and you switch it to On in Watchers.

Once a rule is in use, the button becomes Manage in Intelligence, which opens its operational view.

You need permission to manage watchers in the organization.

Customize​

Customize copies a template into a new rule owned by your organization. The copy:

  • is titled … (custom), with a new SIGMA id and a related link back to the original;
  • keeps the original's tests;
  • starts in Shadow, and enters its rollout like any rule you write;
  • opens in the watcher editor, where you change the rule and its tests.

The original template isn't changed. Only SIGMA rules can be customized: graph detections are maintained by Huntbase. Huntbase-authored rules can't be customized yet.

For your own rules, Edit rule opens the rule in the editor instead.

New detection​

Select New › New detection at the top of the Library to write a SIGMA rule from scratch in the watcher editor, with its tests. New rules start in Shadow. See Watchers for the editor.

SigmaHQ rules​

SigmaHQ publishes thousands of community Sigma rules under the Detection Rule License (DRL) 1.1. Huntbase doesn't ship them. Instead, an organization admin fetches them into their own organization from the SigmaHQ rules card at the top of the Detections catalog.

Enable SigmaHQ rules​

  1. Read the licence linked on the card.
  2. Tick I have read and accept the Detection Rule License 1.1 on behalf of your organization.
  3. Select Enable SigmaHQ rules.

Huntbase fetches the latest SigmaHQ release and compiles every rule. The card shows progress while it runs. Rules that compile are added to your organization as its own rules, turned off (digest only). Nothing runs until you enable a rule, one rule at a time: select Enable for my org on its template in the Library, or switch it on in Watchers.

Every SigmaHQ rule keeps its author, its SigmaHQ id and a link to its source. Its origin reads SigmaHQ, here and in Intelligence › Detections.

Once enabled​

The card shows how many SigmaHQ rules your organization has, how many are enabled, the SigmaHQ release they came from, when they were last synced, and who accepted the licence and when.

  • Re-sync fetches the latest SigmaHQ release again. New rules are added and changed ones are updated.
  • Remove deletes every SigmaHQ rule your organization imported, including enabled ones, after you confirm. Your other rules aren't affected. You can enable SigmaHQ again later.
  • Runs, or N failed to compile, lists recent runs. For each run it shows how many rules it read, compiled, added, updated and left unchanged, and Why rules failed groups the rules that didn't compile by reason, such as missing field User on hb_process_activity, with a count and example rules.
  • If the last run failed, the card shows the error. Select Re-sync to try again.

Only organization admins and owners can enable, re-sync or remove. Everyone else sees the status, or Ask an org admin to enable SigmaHQ rules.

Next steps​