
Detection engineering deserves better.
Build, share, and investigate threats with 17,000+ detection engineers.
Put Enterprise to work researching threats, running hunts, checking coverage, and building detections. Autonomously.
Hunting, coverage, and detection work in one place.
Free for the community. Built for the teams who have to answer for it.



Used by 17,000+ detection engineers. Join them.
Already have a code?
Join Community847+ detection engineers joined this week
One product. Community to enterprise.
Community
Free, forever
- Borrow from tens of thousands of community detections
- Unlimited AI Assistant to generate and refine detections
- Translate across 9 languages
- MITRE ATT&CK mapping on every detection
- Save searches and get email alerts when new detections land
- Publish and build your detections
Enterprise
For your team
- Automated hunting on every relevant report, with draft detections queued for review
- See your live coverage across your detection stack: CVE, MITRE ATT&CK, historical trends
- Close the gaps with detections tuned to your environment and your data sources
- AI Routines that audit and tune your library on a schedule
- Private team workspace, governance, and deploy back to your SIEMs
Live activity from the Hive
Cling Botnet Abusing STUN Infrastructure for C2
9h agoShinyHunters Healthcare Identity Extortion and PeopleSoft Exploitation
9h agoCritical Unpatched Citrix NetScaler RCE Zero-Days Exploited
7d agoAdversaries Abuse ChatGPT Custom GPTs for ClickFix Infections
6d agoFortiMail Path Traversal Zero-Day Under Active Exploitation
9h ago
Webelieveinaworldwheredetectionengineersworktogether.Wheretheknowledgecompoundsinsteadofresets.Wherearulewrittenatonecompanymakeseverycompanyfaster.Wherethecommunitymovesfasterthanthethreatbecausenobodyissolvingthesameproblemtwice.
No more starting from scratch
Someone already wrote it. Find it. “Borrow” it. Make it yours.
Browse rules built by engineers who faced the same threats you are facing right now.

Thousands of contributions from our community.
0
detections used by the community
Come build with us
Join the community that moves faster than the threat.
Running a detection team? See Enterprise →