No plans, no billing

Everything here is free

There is no Pro tier, no subscription and nothing to buy. All 1139 detections — queries, response playbooks, investigation guides and Atomic Red Team tests — are open to everyone, with or without an account.

1139
Detections
14
ATT&CK tactics
347
CVE detections
4126
Atomic tests
£0 forever, for everything below
  • Detection queries for all 7 SIEM platforms — Sentinel (KQL), Splunk (SPL), Elastic, QRadar, Sumo Logic, Chronicle and LogScale
  • Required data sources, tables and sourcetypes for every rule
  • False-positive guidance and tuning notes
  • Response playbooks — triage, containment, evidence collection and escalation criteria
  • Investigation guides with forensic artifacts and hunting queries
  • Atomic Red Team test cases with commands and expected telemetry
  • MITRE ATT&CK coverage matrix and per-tactic browsing
  • CVE / CISA KEV vulnerability detections, updated by the nightly research pipeline
  • Bulk export of the whole corpus as JSON or CSV
  • Public REST API — no key, no rate-limit tiers

1139 of the 1139 detections ship a full response playbook; coverage grows as the pipeline backfills the rest.

The one exception: Detection Playground

LIMITED PREVIEW

The playground — which matches detection logic against your own log events in the browser — is still in limited preview and not yet open. It is not for sale either; when it opens it will be free like everything else.

Questions

Is this really free?

Yes. Every detection, playbook, investigation guide and atomic test on this site is free to read, download and deploy — including in client environments. There is no paid tier and nothing to buy.

Do I need an account?

No. Everything is readable without signing in, and the API and bulk exports are open. New registrations are closed at the moment; existing accounts still work.

Do I own the detection content I export?

Yes. Bulk exports (JSON, CSV) are yours to keep and deploy however you like, including in client environments. Check the licence in the open-source repository for the exact terms.

How often is new content added?

An automated research pipeline turns newly exploited CVEs into detections daily, and ATT&CK technique coverage is extended continuously. The newsletter is the easiest way to hear about new rules.

What about the Detection Playground?

The playground is the one feature still in limited preview and is not open yet. It is not for sale — when it opens it will be free like the rest of the site.

Get new detections in your inbox

New ATT&CK coverage plus CISA KEV / CVE detection rules, roughly weekly. No spam, unsubscribe anytime.