Turn an indicator, CVE, or MITRE ATT&CK technique into a starter detection rule in the format your stack uses. Everything is generated deterministically in your browser — no accounts, no data leaves the page.
# ---------------------------------------------------------------
# Cyronix Threat Intelligence - generated detection TEMPLATE
# Format: Sigma | Input: ATT&CK technique T1021
# STATUS: TEMPLATE - review, test, and tune before production use.
# Generated: 2026-10-05T13:48:48.482Z
# ---------------------------------------------------------------
title: Cyronix - Remote Services (T1021)
status: experimental
description: |
Starter detection for ATT&CK T1021 (Remote Services).
Using RDP, SMB, SSH, or similar to move between systems with valid access.
Replace the placeholder selection with behavior specific to your environment.
logsource:
product: windows
category: process_creation
detection:
selection:
# TODO: encode the observable behavior for T1021 here
Image|endswith: '\\example.exe'
condition: selection
level: medium
tags:
- attack.t1021
- attack.lateral_movement
These are deterministic starter templates, not AI-generated and not production-validated. Review, test against your log schema, and tune before deploying. Generated locally in your browser.
Each rule is a scaffold: it wires up the right structure and the indicator, but placeholders marked TODO must be filled with behavior specific to your environment, and field names must be matched to your log schema. Test in a staging pipeline before enabling in production. For 5 indicator types across six formats, start from an exploited CVE or a technique in the ATT&CK Explorer and generate a matching rule.
No. They are produced by deterministic templates, so the same input always yields the same output. They are starter scaffolds, not AI guesses, and are explicitly not production-validated.
Not safely. Each rule contains placeholders and generic field names that must be adapted to your environment and log schema, then tested. Treat the output as a well-structured starting point that saves you boilerplate.
Sigma, YARA, Suricata, Snort, KQL for Microsoft Sentinel and Defender, and Splunk SPL. The available formats change based on the indicator type — for example, YARA is offered for file hashes, and Suricata/Snort for network indicators.
No. Rule generation runs entirely client-side. Your indicators are never transmitted, logged, or stored.