Detection Version Control
Track every change to your detection rules with complete version history. Compare any two versions side by side and revert when needed.
Detection versioning gives your team full auditability over rule changes. Every save creates an immutable version. Nothing is ever overwritten. You can review what changed, when, and by whom, then compare versions to understand the impact of each edit before promoting or reverting.
Key Concepts
Before working with versioning, understand these core concepts:
| CONCEPT | DESCRIPTION |
|---|---|
| Version | An immutable snapshot created each time a detection rule is saved. Versions are numbered sequentially (v1, v2, v3…) and cannot be modified after creation. |
| Latest | The most recently saved version of a detection rule. Shown with a gray chip in the Journal. |
| Active | The version currently deployed to production. |
| Revert | Creates a new version from an older one. Reverting to v3 does not delete v4 or v5. It allows you to create v6 with v3's content. The version chain is always append-only. |
Viewing Version History
The Journal tab shows every version of a detection rule along with related activity, displayed on a unified timeline.
Open a detection rule and select the Journal tab from the tab bar.
Each version card on the timeline displays:
- The version number and a short description of what changed
- The date and author who created the version
- A Compare button that navigates to the Compare tab with that version pre-selected
Comparing Versions
The Compare tab lets you view a detailed diff between any two versions of a detection rule.
Opening the Compare Tab
From the Journal tab, click the Compare button on any version card. This opens the Compare tab with that version pre-selected as the Base.
Alternatively, select the Compare tab directly from the tab bar.
Use the two dropdowns at the top of the page:
- Base — the older version you are comparing from
- Compare — the newer version you are comparing to
Reading the Diff
When two different versions are selected, the Compare tab displays:
Change History
The full list of changelog journal entries between the selected versions.
Code diff
The rule logic diff renders in a code editor with highlighting identifying where the changes occur.
Change Impact
Below the code diff, the Change Impact section summarizes the broader effect of each version change:
| ROW | DESCRIPTION |
|---|---|
| Query Logic Assessment | An AI-generated summary of how the logic change affects detection behavior. Indicated by a ✨ sparkle icon. |
| Data Coverage | Shows changes to data sources or provider coverage. |
| Schedule & Throttling | Shows changes to execution schedule or throttle settings. |
| MITRE Techniques | Shows added or removed MITRE ATT&CK technique mappings. |
| Severity | Shows changes to the severity of findings from this detection. |
Reverting to a Previous Version
Reverting restores an earlier version's content without losing any history.
-
On the Compare tab, select the version you want to revert to in the Base dropdown, and the current version in the Compare dropdown.
-
Click the Revert to v[x] button on the right side of the dropdown row.
-
In the confirmation dialog, review the warning.
-
Click Update Local Draft to confirm, or Cancel to go back.
After reverting, you are taken back to the edit page where you can save this as a new version. You can then deploy it to make it the Active version.
Reverting does not automatically deploy the detection. After reverting, you still need to deploy the new version to make it active in production.
Updated 21 days ago