Configure
Detection Content and Detection Engineering
Two related surfaces: browse ATT&CK-aligned content and recommendations, then govern tenant detection policy — rule modes, suppressions, packs, and custom rules. Browsing content does not deploy anything.
Detection Content . /detection-library
Detection Content is the library and recommendation surface. Operators browse detections, content packs, an ATT&CK map, and data-requirement views. A pipeline strip summarizes how many rules sit in reference, curated, compatible, shadow, or active states when the API answers. Recommendations can consider the tenant’s configured security stack and use cases.
Candidates can be routed into Detection Engineering via query parameters. Important: browsing and recommending do not deploy rules. Deployment and mode changes happen only in Detection Engineering.
Detection Engineering . /detection-engineering
This is the governance workbench. With detections:manage, operators load rules, policy packs, runtime status, suppressions, and capabilities; edit draft policy; preview formulas; save; create suppressions; and build custom rules. Sector profiles (balanced, banking, healthcare, high assurance, custom) adjust defaults.
Rule modes include active, shadow, and disabled. Shadow evaluates without manufacturing incidents — useful for validating a rule’s noise before it opens cases. Evaluation mode offers a simplified local workbench when exploring without a live policy API.
Relationship to Hunt Ledger and Automation
Detection Engineering defines ongoing rule policy that can open or enrich incidents as telemetry streams. Hunt Ledger runs scheduled cross-checks and ledger reporting for quiet-period proof of work. Automation orchestrates multi-step response after a case exists.
A hunt is not a substitute for rule governance. A rule pack is not a substitute for overnight proof-of-work reporting. A playbook is not a substitute for either.