Detection Version Control

Track every change to your detection rules with complete version history. Compare any two versions side by side and revert when needed.

Detection versioning gives your team full auditability over rule changes. Every save creates an immutable version. Nothing is ever overwritten. You can review what changed, when, and by whom, then compare versions to understand the impact of each edit before promoting or reverting.

Key Concepts

Before working with versioning, understand these core concepts:

CONCEPTDESCRIPTION
VersionAn immutable snapshot created each time a detection rule is saved. Versions are numbered sequentially (v1, v2, v3…) and cannot be modified after creation.
LatestThe most recently saved version of a detection rule. Shown with a gray chip in the Journal.
ActiveThe version currently deployed to production.
RevertCreates a new version from an older one. Reverting to v3 does not delete v4 or v5. It allows you to create v6 with v3's content. The version chain is always append-only.

Viewing Version History

The Journal tab shows every version of a detection rule along with related activity, displayed on a unified timeline.

Open a detection rule and select the Journal tab from the tab bar.

Each version card on the timeline displays:

  • The version number and a short description of what changed
  • The date and author who created the version
  • A Compare button that navigates to the Compare tab with that version pre-selected

Comparing Versions

The Compare tab lets you view a detailed diff between any two versions of a detection rule.

Opening the Compare Tab

From the Journal tab, click the Compare button on any version card. This opens the Compare tab with that version pre-selected as the Base.

Alternatively, select the Compare tab directly from the tab bar.

Use the two dropdowns at the top of the page:

  • Base — the older version you are comparing from
  • Compare — the newer version you are comparing to

Reading the Diff

When two different versions are selected, the Compare tab displays:

Change History

The full list of changelog journal entries between the selected versions.

Code diff

The rule logic diff renders in a code editor with highlighting identifying where the changes occur.

Change Impact

Below the code diff, the Change Impact section summarizes the broader effect of each version change:

ROWDESCRIPTION
Query Logic AssessmentAn AI-generated summary of how the logic change affects detection behavior. Indicated by a ✨ sparkle icon.
Data CoverageShows changes to data sources or provider coverage.
Schedule & ThrottlingShows changes to execution schedule or throttle settings.
MITRE TechniquesShows added or removed MITRE ATT&CK technique mappings.
SeverityShows changes to the severity of findings from this detection.

Reverting to a Previous Version

Reverting restores an earlier version's content without losing any history.

  1. On the Compare tab, select the version you want to revert to in the Base dropdown, and the current version in the Compare dropdown.

  2. Click the Revert to v[x] button on the right side of the dropdown row.

  3. In the confirmation dialog, review the warning.

  4. Click Update Local Draft to confirm, or Cancel to go back.

After reverting, you are taken back to the edit page where you can save this as a new version. You can then deploy it to make it the Active version.

Reverting does not automatically deploy the detection. After reverting, you still need to deploy the new version to make it active in production.


Did this page help you?