Detection Engineering

Turn threat intelligence, hunt findings, and security insights into detection rules that run in production and generate findings when they match suspicious activity.

Detection Types

Nebulock supports two types of detection rules:

Atomic Detections

These trigger on single suspicious events. A known-bad file hash, a dangerous command execution, or a high-risk privilege escalation. Use these for discrete indicators.

Correlation Detections

These identify patterns across multiple events over time. They catch attack sequences, detect anomalous frequencies, and surface multi-step techniques that single events miss.

You can filter the Detections page by type and manage both from one interface.

Detection Workflows

There are three ways to create a detection rule, each starting from a different point:

From Threat Intelligence
Start with a threat intel report: a new malware family, a nation-state TTP, or an emerging vulnerability. The Detection Agent analyzes the reporting and proposes rules targeting the specific techniques and indicators.

From Hunt Results
Convert hunt findings into detections that catch similar activity in the future. The agent uses your hunt objective, discovered techniques, and telemetry patterns to build the rule. Vespyr, Nebulock's automated hunting agent, can also generate detections automatically after completing hunts.

From Scratch
Describe what you want to detect in natural language, or pick a pre-built concept from the Detection Ideas library. The agent asks clarifying questions about data sources, attack techniques, and edge cases before generating the rule.

Working with Detections

Complete guide covering rule creation, editing (via chat or direct SQL), testing with Retrohunt, and deploying to production. Includes configuration options, deployment prerequisites, and GitHub export.

Track every change with immutable version history. Compare any two versions side by side, understand the impact of logic changes with AI-generated assessments, and revert when needed. Every save creates a new version. Nothing is ever overwritten.

Reference tables (also called lookup tables) are reusable lists of values you join against in detection rules. They let you correlate and enrich event data without hardcoding long lists directly into the detection rule logic.

Testing Before Production

Every detection rule must pass a Retrohunt before deployment. The Retrohunt runs your detection logic against historical data to show how the rule would have performed. This helps you tune logic and reduce false positives before the rule goes live.

Retrohunts return up to 1,000 results. If you hit the limit, the rule is probably too broad and needs refinement.

Related Features

Run Your First Retrohunt — Understand retrohunts beyond detection testing
Review Findings — Triage and resolve findings generated by your rules
Leverage Threat Intel Reports — Turn threat intelligence into detections


Did this page help you?