Skip to content
crafted signal

Feature menu

Choose a feature set.

Each page explains the problem, the operating model, the product surfaces, and the handoff to adjacent parts of the platform.

01 · Risk

Risk Modeling

Turn business services, crown-jewel data, and attack paths into detection priorities your SOC can defend.

  • Business services and data assets become first-class SOC inputs.
  • ATT&CK techniques are weighted by exposure, not counted equally.
  • Risks flow into hunts, detections, reports, and audit trails.
02 · Threat

Threat Intelligence

Convert threat briefs, IOCs, Sigma rules, and pentest findings into relevant hunts and detections.

  • Curated briefs include rules, tests, IOCs, runbooks, playbooks, ATT&CK mappings, and affected products.
  • Relevance is calculated against your modeled business and technology context.
  • Briefs can be adopted, hunted, watchlisted, dismissed, or mirrored for air-gapped use.
03 · Hunt

Threat Hunting

Run hypothesis-driven hunts across SIEMs, cluster the hits, verdict the result, and promote what works.

  • Create hunts from risks, threat briefs, pentest findings, or analyst prompts.
  • Run one hypothesis across multiple SIEMs and preserve per-platform result state.
  • Verdict clusters, keep notes, and promote winning queries to tested rules.
04 · Monitor

Detection Health

Catch dead rules, noisy rules, drift, failing tests, and missing context before they become blind spots.

  • One queue for dead rules, drift, failed tests, noise, and missing metadata.
  • Owner-targeted notifications when deployed rules go silent or change out of band.
  • Noise budgets and monitoring mode protect analysts before alerts go live.
05 · Verify

Detection Workflows

Write, test, approve, deploy, and roll back detections with the same discipline teams expect from software delivery.

  • Author in Sigma or native SIEM language with per-rule control.
  • Run positive and negative tests against live Splunk, Sentinel, CrowdStrike, and Rapid7.
  • Attach runbooks and playbooks, keep them in sync with rule changes, and let AI draft or refine both sides.
06 · Operate

Platform Operations

Run CraftedSignal as SaaS, self-hosted, or air-gapped with multi-tenant controls, APIs, CLI, SSO, and local AI.

  • SaaS, single-binary self-hosted, worker split, and air-gapped deployment options.
  • Multi-tenant and white-label controls for MSSP and regulated environments.
  • REST API, Go SDK, csctl, SSO, passkey MFA, RBAC, audit logs, and optional local AI.

Design idea

A product map, not a feature dump.

The site now presents CraftedSignal as a detection engineering control plane: risk decides what matters, threat intel creates relevant work, hunts prove hypotheses, health monitoring keeps coverage alive, workflows make every change reviewable, and operations keep it deployable for real SOC environments.

Input

Business context, threat briefs, pentest findings

Loop

Hunt, test, approve, monitor, improve

Proof

Coverage reports, audit trails, rollback, Git history