Watchers
Library › Watchers is the catalog of watcher templates your organization can use. A template is a watcher you can switch on for your organization as it is, or copy and change into a watcher of your own. The catalog holds:
- Huntbase watchers: the SIGMA and graph watchers Huntbase writes and maintains;
- SigmaHQ rules your organization fetched, each one a watcher (see SigmaHQ rules);
- watchers your org wrote, or customized from a template.
Watchers that are off are listed too. This is what your organization could run. What it does run, and how each watcher performs, is in Intelligence › Watcher health. Every template links to its operational view there, and every watcher there links back to its template here.
Watchers and detections
A watcher is the rule: the logic Huntbase runs over your data, such as a Sigma rule or a graph pattern. Other tools call these "detection rules". When a watcher matches, it fires, and a firing can create a detection. A detection then triggers a hunt or another workflow.
Library › Watchers is part of Intelligence, which is in beta. Access is by request, so it may not be enabled for your organization. It follows the organization selected in the scope selector. Under a personal scope it asks you to choose an organization.
Browse watchers
Open Library and select Watchers in the facet rail. Each template shows as a card, or a row in list view, with:
| Element | What it shows |
|---|---|
| Kind | Watcher · SIGMA, Watcher · Graph or Watcher · Intel |
| Severity and origin | The watcher's default severity, and Huntbase, SigmaHQ or Your org |
| ATT&CK | Up to three technique IDs, with a +N overflow |
| Readiness | Ready on your data, or Needs data when the data the watcher reads isn't arriving in your organization. Hover for the detail. |
| Tests | Passed tests out of the total, or No tests |
| Data source | What the watcher reads, such as Process activity, or Entity graph for a graph watcher |
| In use | Shadow or On when your organization runs the watcher, otherwise Not in use |
The search box at the top matches watcher names, identifiers and techniques. Use the filters to narrow the catalog. Every option shows how many templates it matches across the whole catalog.
| Filter | What it does |
|---|---|
| Tactic / Technique | MITRE ATT&CK tactic or technique |
| Data source | The data the watcher reads |
| Origin | Huntbase, SigmaHQ or Your org |
| Severity | Critical, High, Medium, Low or Informational |
| Readiness | Ready on your data or Needs data |
Applied filters show as chips under the filters. Remove one from its chip, or select Clear all.
A template
Select a card to open the template in a side panel. Full page opens it on its own page, with a link you can share. The template shows:
- its description, origin, severity, the data it reads and whether it can fire on your data;
- whether your organization uses it, in Shadow or On, and where it is in its rollout;
- its ATT&CK techniques, each linking to MITRE ATT&CK;
- the rule: the SIGMA for your own watchers and SigmaHQ rules, or a description for graph and intel watchers. The SIGMA source of Huntbase-authored watchers isn't shown;
- its tests and their last run. Run tests runs them now. You can edit the tests of your own watchers.
Enable for my org
Enable for my org switches the watcher on for your organization in Shadow. Its firings go to the daily digest without notifying anyone or opening hunts, and it never goes straight to On.
- For your own watchers and SigmaHQ rules, if automated rollout is on for your deployment, the watcher also enters its rollout. The rollout promotes it from shadow once its tests, backtest and shadow period pass. See Rollout.
- Otherwise, promote it yourself once you've seen it run: Intelligence › Watcher health shows a Promote hint when a shadow watcher looks ready, and you switch it to On in Watchers.
Once a watcher is in use, the button becomes Manage in Intelligence, which opens its operational view.
You need permission to manage watchers in the organization.
Customize
Customize copies a template into a new watcher owned by your organization. The copy:
- is titled … (custom), with a new SIGMA
idand arelatedlink back to the original; - keeps the original's tests;
- starts in Shadow, and enters its rollout like any watcher you write;
- opens in the watcher editor, where you change the rule and its tests.
The original template isn't changed. Only SIGMA watchers can be customized: graph watchers are maintained by Huntbase. Huntbase-authored watchers can't be customized yet.
For your own watchers, Edit rule opens the watcher in the editor instead.
New watcher
Select New › New watcher at the top of the Library to write a watcher from scratch as a SIGMA rule in the watcher editor, with its tests. New watchers start in Shadow. See Watchers for the editor.
SigmaHQ rules
SigmaHQ publishes thousands of community Sigma rules under the Detection Rule License (DRL) 1.1. Huntbase doesn't ship them. Instead, an organization admin fetches them into their own organization from the SigmaHQ rules card at the top of the Watchers catalog.
Enable SigmaHQ rules
- Read the licence linked on the card.
- Tick I have read and accept the Detection Rule License 1.1 on behalf of your organization.
- Select Enable SigmaHQ rules.
Huntbase fetches the latest SigmaHQ release and compiles every rule. The card shows progress while it runs. Each rule that compiles is added to your organization as a watcher of its own, turned off (digest only). Nothing runs until you enable a watcher, one at a time: select Enable for my org on its template in the Library, or switch it on in Watchers.
Every watcher built from a SigmaHQ rule keeps the rule's author, its SigmaHQ id and a link to its source. Its origin reads SigmaHQ, here and in Intelligence › Watcher health.
Once enabled
The card shows how many SigmaHQ rules your organization has, how many are enabled, the SigmaHQ release they came from, when they were last synced, and who accepted the licence and when.
- Re-sync fetches the latest SigmaHQ release again. New rules are added and changed ones are updated.
- Remove deletes every watcher your organization imported from SigmaHQ, including enabled ones, after you confirm. Your other watchers aren't affected. You can enable SigmaHQ again later.
- Runs, or N failed to compile, lists recent runs. For each run it shows how many rules it read, compiled, added, updated and left unchanged, and Why rules failed groups the rules that didn't compile by reason, such as missing field User on hb_process_activity, with a count and example rules.
- If the last run failed, the card shows the error. Select Re-sync to try again.
Only organization admins and owners can enable, re-sync or remove. Everyone else sees the status, or Ask an org admin to enable SigmaHQ rules.
Next steps
- Intelligence › Watcher health: what your watchers do, day to day
- Watchers: switch watchers on and off, and tune them
- Hunt playbooks