Create and Deploy Detection Rules
Detection rules generate findings when suspicious activity matches your logic. Create rules from threat intelligence, hunt results, or from scratch, then test and deploy them to production.
Understanding Detection Rules
Nebulock supports two types of detection rules:
| TYPE | DESCRIPTION |
|---|---|
| Atomic | Detects suspicious activity from a single event. Triggers immediately when an individual log entry matches your filter conditions. Use for known-bad indicators and discrete suspicious actions. |
| Correlation | Detects patterns across multiple events over time. Uses correlation logic to identify attack sequences, anomalous frequency, or multi-step techniques. These are currently marked as "Scheduled" types in some parts of the Ui. |
Filter the Detections page by rule type to view only Atomic or Correlation detections.
Creating Detection Rules
There are three ways to create a detection rule in Nebulock:
From Threat Intelligence
Generate rules targeting specific TTPs, malware families, or threat actors from a threat intel report.
- Navigate to Intel > Threat Intel from the left sidebar
- Find a relevant threat intel report
- Click + Create Detection Rule at the bottom of the report page
- Select a Log Source from the dropdown (Cloud, IAM, Linux, Mac OS, Windows)
- (Optional) Add Additional Instructions to guide rule generation
- Click Start Detection Rule Generation
The Detection Agent opens with the threat intel content as context and begins analyzing the threat to propose detection logic.
From a Hunt
Convert hunt findings into detections that catch similar activity in the future.
- Navigate to Hunt > Hunts or Hunt Reports
- Open a completed hunt
- Ask the agent to create a detection rule, or accept the agent recommendation to create rules.
The agent uses context from your hunt session (the objective, findings, and telemetry patterns) to build the rule.
Vespyr, Nebulock's automated hunting agent, can also create detections automatically after completing hunts, with no user input required.
From Scratch
Build a rule from your own detection idea without hunt or threat intel context.
- Navigate to Detections from the left sidebar
- Click + Create Detection Rule in the top-right corner
- In the chat interface, describe what you want to detect
Or select a pre-built concept from the Detection Ideas sidebar on the left.
The agent may ask clarifying questions about data sources, attack techniques, or edge cases before generating the rule.
Editing Detection Rules
Once a rule is generated, refine it using the Detection Agent or by editing the SQL directly.
Chat with the Detection Agent
The Detection Agent panel appears on the right side of every detection rule page. Use it to request changes conversationally:
- "Reduce false positives by excluding system accounts"
- "Add a condition for processes spawned by Office applications"
- "Change severity to High"
The agent displays proposed changes and asks you to apply or discard them.
Direct SQL Editing
For precise control, edit the detection logic directly:
- Open a detection rule
- Find the Filter Conditions section showing the SQL logic
- Click into the code editor to modify the query
- Click Save in the top-right when finished
If you save a rule with syntax errors, you'll see a "Failed to Save Rule" error message. Use the agent chat to identify and resolve the syntax error if needed.
Configuration Options
Below the detection logic, configure how the rule runs and what findings it generates:
| SETTING | DESCRIPTION |
|---|---|
| Bind Parameters | Define reusable variables referenced in your query logic. Click + Add parameter to create new bindings. |
| Signal Severity | Set the severity level (Informational, Low, Medium, High, Critical) for findings generated by this rule. |
| AI Tags | Automatically applied MITRE ATT&CK techniques, tactic collections, and platform tags based on your rule's logic and description. |
For Correlation rules, additional settings control execution timing:
| SETTING | DESCRIPTION |
|---|---|
| Run Frequency | How often the scheduled query executes (e.g., every 5 minutes, hourly, daily). |
| Window Duration | Suppression period after the first event is detected. Prevents alert storms from repeated activity by the same user or host. |
| Group By | Field used to group events by entity, typically endpoint or user. Determines which events are considered part of the same pattern. |
Testing with Retrohunt
Before deploying a rule to production, run a Retrohunt to validate it against historical data. This shows how the rule would have performed over past telemetry and helps tune logic to reduce false positives.
- Scroll to the Retrohunt Results section at the bottom of the rule page
- (Optional) Select a custom Range from the dropdown to test a specific time period
- Click Run Retrohunt
The Retrohunt executes your detection logic against historical logs. Results appear in the same section.
Results display in a table. You can customize which columns appear, search through all available fields in the returned events, and choose which to display as columns.
NOTE: A Retrohunt can run over a maximum of 14 days of data. Retrohunts return a maximum of 1,000 results. If you see 1,000 results, you hit the limit. This usually means the rule is too broad and needs refinement.
Deploying Detection Rules
After you've tested a rule and are satisfied with the results, deploy it to production so it begins generating findings in real time.
Deployment Prerequisites
The Deploy button in the top-right corner becomes available only when all prerequisites are met:
- Save Status — The rule and all modifications must be saved
- Validation — No SQL syntax or field naming errors
- Retrohunt — A retrohunt must have completed successfully on the current saved version
If prerequisites are incomplete, the Deploy button appears grayed out. Hover over it to see which requirements are failing.
Deploying the Rule
Once all prerequisites are met:
- Click Deploy in the top-right corner
- Confirm deployment in the dialog that appears
The rule's status changes from "inactive" to "active" and begins processing live telemetry. Findings generated by the rule appear on the Monitor > Findings page.
Exporting to GitHub
If your team maintains detection rules in a GitHub repository, you can export rules directly from Nebulock via a Workflow Integration.
Prerequisites
GitHub integration must be configured in Settings > Integrations before you can export rules. See the Integrations documentation for setup instructions.
Exporting a Rule
- Open the detection rule you want to export
- Click the ⋮ menu button in the top-right corner (next to the Save button)
- Select Actions > Push to Github
The rule is exported to your configured repo.
Updated 20 days ago