04 · Monitor
Detection Health
Catch dead rules, noisy rules, drift, failing tests, and missing context before they become blind spots.
- One queue for dead rules, drift, failed tests, noise, and missing metadata.
- Owner-targeted notifications when deployed rules go silent or change out of band.
- Noise budgets and monitoring mode protect analysts before alerts go live.

Signal
Know when a rule stops working
Per-rule health and firing history expose silent failures before an incident does.
Control
Noise is budgeted
Rules that exceed expected volume can be held, tuned, or left in monitoring mode.
Audit
Drift is visible
Out-of-band SIEM edits are hashed, diffed, and queued for review.
The problem
Shipping a rule is not the end of detection engineering. Rules go silent because logs change, fields drift, integrations break, upstream products update, or someone edits the detection directly in the SIEM. Other rules keep firing but become too noisy for analysts to trust.
Traditional dashboards make this hard to see. Noise, rule health, test failures, coverage, direct SIEM edits, and missing metadata often live in different places. By the time a team notices, the first reliable signal may be an incident review.
How CraftedSignal monitors detections
CraftedSignal keeps health signals attached to the rule lifecycle. Each deployed rule can show recent firing behavior, test status, drift state, noise budget impact, ownership, platform deployment state, and coverage context.
The platform surfaces one operational queue for rules that need attention: dead rules, unexpectedly noisy rules, drifted rules, failing tests, missing ATT&CK mappings, missing owners, and other quality issues. The queue is designed for action, not just observation.
Recommendations turn those signals into next steps: tune this rule, add tests, fix this mapping, review stale runbooks and playbooks, generate a rule for this coverage gap, or retire low-value content.
Noise, drift, and silent failure
Noise budgets set an expected alert volume by company, team, service, or rule. New detections can run in monitoring mode first, producing measurement without paging analysts. If expected volume is too high, the rule can be tuned before it becomes active.
Drift detection compares the running SIEM version to the version CraftedSignal last deployed. If a rule changes outside the controlled workflow, the platform shows the diff and queues it for review. That protects both auditability and operational trust.
Silent rules are handled as a first-class health issue. When a rule that normally fires stops producing signal, the owner can be notified and the SOC can decide whether telemetry changed, the threat disappeared, or coverage broke.
What leaders get
SOC leaders get a Monday-morning view of the work that matters: exposure, broken detections, noisy detections, uncovered techniques, and workload. The goal is not to count rules. The goal is to know which protections are alive, which need attention, and which risks remain open.
Related docs
Go deeper in the technical docs.
Health & Analytics
Coverage, health queues, workload metrics, MTTD, MTTR, and ROI views.
Drift Detection
How deployed rules are re-hashed, diffed, and reviewed after out-of-band changes.
Noise Budgets
Daily alert limits by company, team, service, and rule.
Recommendations
Prioritized action queue for coverage, tuning, mappings, and stale response steps.
AI Quality
Owner-facing metrics for AI operation quality, retries, errors, and proposals.
Git-native Backups
Scheduled Git mirrors for rules, versions, tests, and restore points.
Next feature sets