Detection Packages

Free detection rules for every MITRE ATT&CK technique. Upgrade to Pro for complete purple team packages.

Free

£0 /month
  • KQL detection rules (Microsoft Sentinel)
  • SPL detection rules (Splunk)
  • MITRE ATT&CK coverage matrix
  • Required data sources and tables
  • False positive guidance

Not included

  • Response playbooks per technique
  • Atomic Red Team test cases
Want playbooks & atomic tests? See Pro → Managing multiple client environments? See MSP Pack → Browse Detections
Best Value

Pro

£29 /user/month

1075 detections, each with a full playbook & atomic tests — across 14 MITRE ATT&CK tactics

  • Everything in Free
  • Response playbooks per technique
  • Investigation guides with forensic artifacts
  • Atomic Red Team test cases
  • Bulk export (JSON, YAML, CSV)
  • REST API access
Sign Up to Upgrade

Cancel anytime, no long-term contract

MSP Pack

MSP Pack

£299 /month

Up to 5 tenants

See full MSP Portal details → Need more than 5 tenants? See Enterprise →

Deploy all 1075 detections ( 14 MITRE tactics covered) to up to 5 tenants

  • Everything in Pro
  • Multi-tenant license — one subscription covers up to 5 client environments
  • MSP portal — bundle stats and one-click bulk download for client redeployment
  • Curated SMB detection bundle (35+ rules)
  • Threat-intel tagged detections (CVE & actor-linked)
  • New rules pushed as threats emerge
  • All 7 SIEM platforms (Sentinel, Splunk, Elastic, QRadar, Sumo, Chronicle, LogScale)
Sign Up for MSP Pack

Cancel anytime, no long-term contract

Contact Us

Enterprise

Custom

For MSSPs and SOC teams

  • Everything in Pro
  • Bulk API access for multi-tenant deployment
  • Priority support
  • Custom integrations
  • Volume licensing
  • Dedicated onboarding
Contact Us

Compare Features

Feature Free Pro MSP Pack Enterprise
KQL detection rules (Microsoft Sentinel)
SPL detection rules (Splunk)
MITRE ATT&CK coverage matrix
Required data sources and tables
False positive guidance
Response playbooks per technique
Investigation guides with forensic artifacts
Atomic Red Team test cases
Bulk export (JSON, YAML, CSV)
REST API access
Curated SMB detection bundle (35+ rules)
Threat-intel tagged detections (CVE & actor-linked)
New rules pushed as threats emerge
All 7 SIEM platforms (Sentinel, Splunk, Elastic, QRadar, Sumo, Chronicle, LogScale)
Bulk JSON download — deploy to any tenant
Bulk API access for multi-tenant deployment
Priority support
Custom integrations
Volume licensing
Dedicated onboarding

Frequently Asked Questions

Can I cancel my subscription at any time?

Yes. Cancel anytime from your account settings — there are no cancellation fees and no minimum term. You keep full access to your plan until the end of the billing period you already paid for.

Can I switch between monthly and annual billing?

Yes. Use the Monthly / Annual toggle on the Pro card to switch billing cycles at any time. Annual billing works out to 2 months free compared to paying monthly, and your next invoice reflects the new cycle.

What happens if I need more than 5 tenants on the MSP Pack?

The MSP Pack covers up to 5 tenants. If you manage more, contact us about Enterprise — we offer custom multi-tenant volume licensing and bulk API access sized to your MSSP or SOC.

Do I own the detection data I export?

Yes. Bulk exports (JSON, YAML, CSV) are yours to keep and deploy however you like, including in client environments. If you cancel, anything you already exported remains fully usable — you just stop receiving new rules and updates.

Do you offer refunds?

If you're not satisfied, contact us at [email protected] within 14 days of your purchase and we'll issue a full refund, no questions asked. After that window, you can still cancel anytime to stop future billing.