Reference Tables

Reference tables (also called lookup tables) are reusable lists of values you join against in detection rules. They let you correlate and enrich event data without hardcoding long lists directly into the detection rule logic.

Why Use Reference Tables

It's far easier to understand and maintain a reference list than a giant list of values in a detection rule.

Detection rules often need to check if a value appears in a list: known LOLBins, suspicious domains, malware hashes, or organizational context like VIP users. Hardcoding these values creates problems:

  • Every rule duplicates the same list
  • Updates require editing every rule
  • Long lists of values make rules hard to read and maintain

Reference tables solve this. Instead of writing dozens of process names, domains, or hashes into every rule, you can create a reference table once in the Nebulock platform and reference it across multiple detections. When you update the table by adding a new value or removing one, every rule that uses it inherits the change immediately.

Common Use Cases

USE CASEDESCRIPTION
Threat IntelligenceDomains, IPs, file hashes from threat intel feeds.
Alert SuppressionKnown good processes, approved domains, trusted IPs. Allowlists that reduce false positives.
LOLBinsLiving-off-the-land binaries attackers abuse. Catalog the common files used and detect suspicious use of legitimate tools.
Suspicious PatternsFile extensions, registry keys, command patterns associated with attacks.

Nebulock-Provided Reference Tables

Nebulock includes pre-built reference tables you can use immediately in your detection rules. These tables are maintained by Nebulock's DE/TH team and are updated regularly.

Available Tables:

These tables are read-only. To customize them for your environment, use the Clone option to create a new version of the list that you own, and edit the values as you see fit.

Creating Reference Tables

  1. Navigate to Detections > Reference Tables from the left sidebar
  2. Click + Create Reference Table in the top-right corner
  3. Enter a Table Name.
    1. The slug value will be created automatically. This value is used in the detection rule and only accepts alphanumeric characters and dash.
  4. Add a Description of what the table contains and when to use it
  5. Add the Field value you wish to create a table for, e.g "dns.question.name"
    1. Use the Schema Field Reference Guide to find the right field.
  6. Add values:
    • Click + Add Value to enter items one at a time
    • Or click Bulk Import to import a CSV file.
  7. Click Save

The reference table is now available for any of your detection rules.

Managing Reference Tables

Editing Values

  1. Navigate to Detections > Reference Tables
  2. Open the reference table you want to modify
  3. Add new values with + Add Value or remove existing ones
  4. Click Save

All detection rules that reference this table immediately use the updated list. No redeployment needed.

Viewing References

Each reference table page shows which detection rules currently use it. Check this to understand the impact of changes before updating the table.

Deleting Reference Tables

You cannot delete a reference table while detection rules still reference it. Remove the table from all rules first, then delete it.

Best Practices

  • Document the source of values in the table description. If the list comes from MITRE, a threat intel feed, or organizational policy, note it so future maintainers understand where it came from.
  • Keep tables focused on one concept. Don't mix LOLBins and malicious domains in the same table. Separate tables are easier to maintain and reason about.
  • Test after updates by running a Retrohunt on rules that reference the table. This confirms that new values don't introduce unexpected false positives.

Related Features

Create and Deploy Detection Rules — Complete guide to detection rule creation and testing
Detection Versioning — Track changes to detection logic over time


Did this page help you?