Skip to content
crafted signal

Feature menu

Choose a feature set.

Each page explains the problem, the operating model, the product surfaces and the handoff to adjacent parts of the platform.

01 · Risk

Risk Modeling

Turn business services, crown-jewel data, attack paths, threats and findings into risk-scored detection priorities your SOC can defend.

  • Start with manual input, regular imports, or a plain-text asset description.
  • ATT&CK techniques, telemetry and findings are weighted by exposure, not counted equally.
  • Risks flow into Backlog items, hunts, detections, reports, and audit trails.
02 · Threat

Threat Intelligence

Convert threat briefs, IOCs, Sigma rules, CVEs and ethical hack findings into risk-scored Backlog work, hunts and detections.

  • Curated briefs include rules, tests, IOCs, runbooks, playbooks, ATT&CK mappings and affected products.
  • Relevance is calculated against your business surface, technology stack, telemetry and rules.
  • Briefs can be marked affected, marked not affected, adopted, hunted, watchlisted, dismissed, or mirrored for air-gapped use.
03 · Hunt

Threat Hunting

Run hypothesis-driven hunts across SIEMs, cluster the hits, verdict the result and promote what works.

  • Create hunts from risks, threat briefs, ethical hack findings, or analyst prompts.
  • Run one hypothesis across multiple SIEMs and preserve per-platform result state.
  • Verdict clusters, keep notes and promote winning queries to tested rules.
04 · Monitor

Detection Health

Catch dead rules, noisy rules, drift, failing tests, missing telemetry and weak mappings before they become blind spots.

  • One Backlog for dead rules, drift, failed tests, false positives, missing telemetry, and missing metadata.
  • Owner-targeted notifications when deployed rules go silent or change out of band.
  • Noise budgets and monitoring mode protect analysts before alerts go live.
05 · Verify

Detection Workflows

Write, test, approve, deploy, and roll back detections with the same discipline teams expect from software delivery.

  • Author in Sigma or native SIEM language with per-rule control.
  • Run positive and negative tests against live Splunk, Sentinel, CrowdStrike, and Rapid7.
  • Attach runbooks and playbooks, keep them in sync with rule changes, and draft or refine both sides under review.
06 · Operate

Platform Operations

Run CraftedSignal as SaaS, self-hosted, or air-gapped with hardened GCP infrastructure, multi-tenant controls, APIs, CLI, SSO, and optional local generation.

  • SaaS on private GCP infrastructure, single-binary self-hosted, worker split, and air-gapped deployment options.
  • Multi-tenant and white-label controls for MSSP and regulated environments.
  • REST API, Go SDK, csctl, SSO, passkey MFA, RBAC, audit logs, KMS-backed controls, and optional local models.

Design idea

A product map, not a feature dump.

The site now presents CraftedSignal as a detection engineering control plane: risk decides what matters, threat intel creates relevant work, hunts prove hypotheses, health monitoring keeps coverage alive, workflows make every change reviewable and operations keep it deployable for real SOC environments.

Input

Business context, threat briefs, ethical hack findings

Loop

Hunt, test, approve, monitor, improve

Proof

Coverage reports, audit trails, rollback, Git history