What problem does it solve? Security teams struggle to search, compare, and measure coverage across thousands of detection rules scattered across Sigma, Splunk, Elastic, KQL, Sublime, and CrowdStrike repositories, making gap analysis against MITRE ATT&CK slow and manual. ## Core Features & Use Cases - Unified Detection Search: Query 8,200+ rules across six detection formats through a single MCP interface with filters for technique, tactic, CVE, severity, and process name. - Coverage & Gap Analysis: Analyze detection coverage by tactic, technique, or threat actor, identify weak spots, and export ATT&CK Navigator layers for visualization. - Detection Engineering Workflows: Generate new detection rules from descriptions or templates, learn patterns from existing rules, and plan detection sprints. - Use Case: A detection engineer assessing ransomware readiness runs the ransomware-readiness-assessment prompt, identifies missing techniques in the kill chain, generates a gap Navigator layer, and drafts new Sigma rules for uncovered techniques. ## Quick Start Ask the AI to search for security detections covering ransomware and analyze your detection coverage gaps against MITRE ATT&CK.