ThreatNexaris

Hunting and detection

Hunts that open in your console.

Detection content arrives mapped to the technique it covers and written in your platform's own query language, using your index and your field names, with a link straight into your console. Not a snippet somebody has to translate before it runs.

  1. 01

    Ten platforms, native output

    Queries generated for Elastic, Splunk, Sentinel, QRadar, Chronicle, CrowdStrike, Defender, SentinelOne, Carbon Black and Cortex XDR, each in that platform's own language.

  2. 02

    Mapped to technique, not to a blog post

    Every piece of detection content is tied to the adversary technique it covers, so coverage is a question you can answer rather than a feeling.

  3. 03

    Coverage you can see and track

    Which techniques you detect, which you do not, and which matter most for the threats currently pointed at your sector.

  4. 04

    A hunt has a lifecycle

    Hypotheses, ownership, comments and outcomes, so a hunt that found nothing is recorded as having been run rather than quietly forgotten.

Query languages generated
Elasticsearch / Kibana
KQL
Splunk
SPL
Microsoft Sentinel
Sentinel KQL
IBM QRadar
AQL
Google Chronicle / SecOps
YARA-L
CrowdStrike Falcon
FQL
Microsoft Defender for Endpoint
MDE KQL
SentinelOne
S1QL
VMware Carbon Black
CB Query
Palo Alto Cortex XDR
XQL

What we commit to

Things that stay true, or they are defects.

  • Your fields, not ours

    Field mappings and index names are held per platform per customer, so a query runs as written.

  • Exportable

    Indicator lists, structured intelligence and detection content leave in open formats.

  • Nothing runs itself

    The platform generates and links. It does not execute anything against your estate on its own.

See it against your own estate.

The useful version of this conversation uses your data, not ours. Bring a vulnerability, a supplier or a domain you already care about.