Skip to content
crafted signal

Documentation

Everything you need to install, configure, and run CraftedSignal.

Getting Started

Core Concepts

Rules

How detection rules are structured in CraftedSignal: metadata, MITRE ATT&CK mapping, multi-platform implementations, lifecycle states, versioning, and dependencies.

Library

Reusable rule and hunt templates with tests, ATT&CK mapping, runbooks, playbooks, comments, imports, and managed source repositories.

Testing

Test detection rules with positive, negative, and enrichment tests run against your live SIEM. Covers validation, CI/CD pipelines, and continuous monitoring.

Deployment & Rollback

Deploy detection rules to Splunk, Sentinel, CrowdStrike, and Rapid7 with approval workflows, dry-run previews, atomic rollback, and drift detection.

Groups

Organize rules into deployable groups with targets, quality status, approval policy, batch deployment, CSV export, and health tracking.

Runbooks & Playbooks

Attach Markdown runbooks and playbooks to rules, hunts, library entries, and threat briefs. Keep response steps synced with rule changes and AI-generated drafts.

Threat Hunting

Hypothesis-driven hunts that fan out across every connected SIEM. Cluster results, verdict them in batch, attach runbooks and playbooks, and promote winning queries to tested Sigma detections with a full audit trail.

Health & Analytics

Monitor detection health with MITRE ATT&CK coverage heatmaps, noise budgets, signal-to-noise ratios, team workload metrics, MTTR, and ROI tracking dashboards.

Risks

The Risk Ops Board turns each company attack path into a tracked risk with a state machine, priority score, and lifecycle audit trail. Hunt, accept residual, escalate, or schedule a re-hunt — the loop closes back into coverage.

Threat Modeling & Risk Scoring

Model business services, declare attack paths, and score every MITRE technique by the exposure it represents to your organization. Accepted paths become tracked risks with a full lifecycle.

Threat Actors

A normalized catalog of threat groups linked to briefs, risks, detections, and hunts. Seeded from MITRE ATT&CK and grown automatically by an LLM that adjudicates names from incoming intel.

Threat Feed

Curated threat briefs with Sigma rules, IOCs, runbooks, playbooks, MITRE mappings, and affected vendor/product/OS metadata. Briefs are scored against your context, related to your modeled risks, and can be adopted, hunted, watchlisted, or dismissed per-tenant.

D3FEND Defensive Coverage

MITRE D3FEND integration: how CraftedSignal maps your active detections to defensive techniques across the Detect, Harden, Isolate, Deceive, and Evict categories — and how gaps feed the hunt proposer.

Threat Intake

SOC triage queue for candidate threats from CTI, risk requests, Threats, and future exposure or vulnerability sources.

Features

Operations

Administration

Integrations

Security