Documentation
Everything you need to install, configure, and run CraftedSignal.
Getting Started
Getting Started
Install CraftedSignal (SaaS or self-hosted), connect your SIEM, import or create detection rules, add runbooks and playbooks, and deploy your first rule in minutes with csctl.
Configuration
Complete YAML configuration reference for CraftedSignal covering HTTP, storage, security, Temporal, AI, email, logging, and production hardening options.
CLI Reference
Full reference for csctl, the CraftedSignal CLI. Covers commands for init, validate, push, pull, sync, diff, library management, and CI/CD integration.
Pricing & Limits
Compare CraftedSignal pricing tiers: Free, Professional, Enterprise, and Unlimited. See rule limits, SIEM connections, API quotas, and self-hosted licensing.
Core Concepts
Rules
How detection rules are structured in CraftedSignal: metadata, MITRE ATT&CK mapping, multi-platform implementations, lifecycle states, versioning, and dependencies.
Library
Reusable rule and hunt templates with tests, ATT&CK mapping, runbooks, playbooks, comments, imports, and managed source repositories.
Testing
Test detection rules with positive, negative, and enrichment tests run against your live SIEM. Covers validation, CI/CD pipelines, and continuous monitoring.
Deployment & Rollback
Deploy detection rules to Splunk, Sentinel, CrowdStrike, and Rapid7 with approval workflows, dry-run previews, atomic rollback, and drift detection.
Groups
Organize rules into deployable groups with targets, quality status, approval policy, batch deployment, CSV export, and health tracking.
Runbooks & Playbooks
Attach Markdown runbooks and playbooks to rules, hunts, library entries, and threat briefs. Keep response steps synced with rule changes and AI-generated drafts.
Threat Hunting
Hypothesis-driven hunts that fan out across every connected SIEM. Cluster results, verdict them in batch, attach runbooks and playbooks, and promote winning queries to tested Sigma detections with a full audit trail.
Health & Analytics
Monitor detection health with MITRE ATT&CK coverage heatmaps, noise budgets, signal-to-noise ratios, team workload metrics, MTTR, and ROI tracking dashboards.
Risks
The Risk Ops Board turns each company attack path into a tracked risk with a state machine, priority score, and lifecycle audit trail. Hunt, accept residual, escalate, or schedule a re-hunt — the loop closes back into coverage.
Threat Modeling & Risk Scoring
Model business services, declare attack paths, and score every MITRE technique by the exposure it represents to your organization. Accepted paths become tracked risks with a full lifecycle.
Threat Actors
A normalized catalog of threat groups linked to briefs, risks, detections, and hunts. Seeded from MITRE ATT&CK and grown automatically by an LLM that adjudicates names from incoming intel.
Threat Feed
Curated threat briefs with Sigma rules, IOCs, runbooks, playbooks, MITRE mappings, and affected vendor/product/OS metadata. Briefs are scored against your context, related to your modeled risks, and can be adopted, hunted, watchlisted, or dismissed per-tenant.
D3FEND Defensive Coverage
MITRE D3FEND integration: how CraftedSignal maps your active detections to defensive techniques across the Detect, Harden, Isolate, Deceive, and Evict categories — and how gaps feed the hunt proposer.
Threat Intake
SOC triage queue for candidate threats from CTI, risk requests, Threats, and future exposure or vulnerability sources.
Features
AI Assistance
AI-assisted detection engineering: rule generation, runbook and playbook drafts, translation linting, health insights, and autofix. Self-hosted via Ollama with full data privacy and human approval.
Secure Detection Workflows
Secure detection workflows with mandatory validation, automated SIEM testing, approval gates, atomic rollback, drift detection, and breakglass emergency procedures.
Approvals
Review rule changes before deployment with query diffs, metadata, tests, projected impact, noise budget context, multi-approver policy, and audit history.
Recommendations
Actionable detection improvements for coverage gaps, tuning, broken rules, missing runbooks and playbooks, mappings, maturity posture, and AI-assisted rule generation.
Operations
Drift Detection
Every deployed rule is re-hashed on a schedule. Any out-of-band change in the SIEM is flagged, diffed, and queued for review.
Noise Budgets
Set daily alert budgets per team, service, or rule. Deploys that would blow the budget are held. Monitoring mode proves volume out before alerts reach analysts.
Git-native Backups
Push every rule, version, and test to your Git repository on a schedule. Restore from any point, audit offline, or migrate environments without touching the SIEM.
Simulations
Run attack simulations from the CLI, report results to the platform, correlate detections, bind scenarios to rules, and track simulated coverage gaps.
Air-gapped Mode
Run the platform with all outbound network access blocked, including DNS. For regulated and isolated environments where the platform must not reach the internet.
Administration
Roles & Permissions
Role-based access control with Owner, Admin, User, and Viewer roles. Covers separation of duties, permission matrix, SSO/OIDC, passkey MFA, and instance claiming.
AI Quality
Track AI operation volume, first-pass rate, quality scores, retries, errors, hot rules, trends, and improvement proposals.
Integrations
API Reference
CraftedSignal REST API reference for CI/CD integration: lint, test, deploy, rollback, approval workflows, health metrics, and rate limits by pricing tier.
Platform Guides
Platform integration guides for Splunk (SPL), Microsoft Sentinel (KQL), CrowdStrike (IOA), and Rapid7 InsightIDR (LEQL) with setup, credentials, and multi-SIEM deployment.
Targets & Mappings
Connect SIEM targets, keep read-only or auto-sync settings, manage field mappings, log source mappings, and apply suggested overrides.