Detection Packages
Free detection rules for every MITRE ATT&CK technique. Upgrade to Pro for complete purple team packages.
Free
- KQL detection rules (Microsoft Sentinel)
- SPL detection rules (Splunk)
- MITRE ATT&CK coverage matrix
- Required data sources and tables
- False positive guidance
Not included
- Response playbooks per technique
- Atomic Red Team test cases
Pro
1075 detections, each with a full playbook & atomic tests — across 14 MITRE ATT&CK tactics
- Everything in Free
- Response playbooks per technique
- Investigation guides with forensic artifacts
- Atomic Red Team test cases
- Bulk export (JSON, YAML, CSV)
- REST API access
Cancel anytime, no long-term contract
MSP Pack
Up to 5 tenants
See full MSP Portal details → Need more than 5 tenants? See Enterprise →Deploy all 1075 detections ( 14 MITRE tactics covered) to up to 5 tenants
- Everything in Pro
- Multi-tenant license — one subscription covers up to 5 client environments
- MSP portal — bundle stats and one-click bulk download for client redeployment
- Curated SMB detection bundle (35+ rules)
- Threat-intel tagged detections (CVE & actor-linked)
- New rules pushed as threats emerge
- All 7 SIEM platforms (Sentinel, Splunk, Elastic, QRadar, Sumo, Chronicle, LogScale)
Cancel anytime, no long-term contract
Enterprise
For MSSPs and SOC teams
- Everything in Pro
- Bulk API access for multi-tenant deployment
- Priority support
- Custom integrations
- Volume licensing
- Dedicated onboarding
Compare Features
| Feature | Free | Pro | MSP Pack | Enterprise |
|---|---|---|---|---|
| KQL detection rules (Microsoft Sentinel) | ||||
| SPL detection rules (Splunk) | ||||
| MITRE ATT&CK coverage matrix | ||||
| Required data sources and tables | ||||
| False positive guidance | ||||
| Response playbooks per technique | — | |||
| Investigation guides with forensic artifacts | — | |||
| Atomic Red Team test cases | — | |||
| Bulk export (JSON, YAML, CSV) | — | |||
| REST API access | — | |||
| Curated SMB detection bundle (35+ rules) | — | — | — | |
| Threat-intel tagged detections (CVE & actor-linked) | — | — | — | |
| New rules pushed as threats emerge | — | — | — | |
| All 7 SIEM platforms (Sentinel, Splunk, Elastic, QRadar, Sumo, Chronicle, LogScale) | — | — | — | |
| Bulk JSON download — deploy to any tenant | — | — | — | |
| Bulk API access for multi-tenant deployment | — | — | — | |
| Priority support | — | — | — | |
| Custom integrations | — | — | — | |
| Volume licensing | — | — | — | |
| Dedicated onboarding | — | — | — |
Frequently Asked Questions
Can I cancel my subscription at any time?
Yes. Cancel anytime from your account settings — there are no cancellation fees and no minimum term. You keep full access to your plan until the end of the billing period you already paid for.
Can I switch between monthly and annual billing?
Yes. Use the Monthly / Annual toggle on the Pro card to switch billing cycles at any time. Annual billing works out to 2 months free compared to paying monthly, and your next invoice reflects the new cycle.
What happens if I need more than 5 tenants on the MSP Pack?
The MSP Pack covers up to 5 tenants. If you manage more, contact us about Enterprise — we offer custom multi-tenant volume licensing and bulk API access sized to your MSSP or SOC.
Do I own the detection data I export?
Yes. Bulk exports (JSON, YAML, CSV) are yours to keep and deploy however you like, including in client environments. If you cancel, anything you already exported remains fully usable — you just stop receiving new rules and updates.
Do you offer refunds?
If you're not satisfied, contact us at [email protected] within 14 days of your purchase and we'll issue a full refund, no questions asked. After that window, you can still cancel anytime to stop future billing.