Turn an indicator, CVE, or MITRE ATT&CK technique into a starter detection rule in the format your stack uses. Everything is generated deterministically in your browser — no accounts, no data leaves the page.
# ---------------------------------------------------------------
# Cyronix Threat Intelligence - generated detection TEMPLATE
# Format: Sigma | Input: ATT&CK technique T1018
# STATUS: TEMPLATE - review, test, and tune before production use.
# Generated: 2026-10-05T13:49:13.330Z
# ---------------------------------------------------------------
title: Cyronix - Remote System Discovery (T1018)
status: experimental
description: |
Starter detection for ATT&CK T1018 (Remote System Discovery).
Identifying other hosts on the network to target for movement.
Replace the placeholder selection with behavior specific to your environment.
logsource:
product: windows
category: process_creation
detection:
selection:
# TODO: encode the observable behavior for T1018 here
Image|endswith: '\\example.exe'
condition: selection
level: medium
tags:
- attack.t1018
- attack.discovery
These are deterministic starter templates, not AI-generated and not production-validated. Review, test against your log schema, and tune before deploying. Generated locally in your browser.
Each rule is a scaffold: it wires up the right structure and the indicator, but placeholders marked TODO must be filled with behavior specific to your environment, and field names must be matched to your log schema. Test in a staging pipeline before enabling in production. For 5 indicator types across six formats, start from an exploited CVE or a technique in the ATT&CK Explorer and generate a matching rule.
No. They are produced by deterministic templates, so the same input always yields the same output. They are starter scaffolds, not AI guesses, and are explicitly not production-validated.
Not safely. Each rule contains placeholders and generic field names that must be adapted to your environment and log schema, then tested. Treat the output as a well-structured starting point that saves you boilerplate.
Sigma, YARA, Suricata, Snort, KQL for Microsoft Sentinel and Defender, and Splunk SPL. The available formats change based on the indicator type — for example, YARA is offered for file hashes, and Suricata/Snort for network indicators.
No. Rule generation runs entirely client-side. Your indicators are never transmitted, logged, or stored.