All features Detection Rule Library

A tunable detection library you switch on per client

Enable curated detection rules per client and tune them without forking. Every rule is version-controlled and mapped to your frameworks and MITRE ATT&CK — so coverage is something you can show, not guess at.

Get started Run a free scan
Per-clienttuning
Versioncontrolled
ATT&CKmapped
detection-rule-library Tuned
RULERule catalogON
TUNEPer-client tuneEDIT
VERSVersion historySAVED
MAPPFramework mapTAG
What it does

Key capabilities

Curated rule catalog

A maintained library of detection rules, grouped by surface and technique. Turn on what fits each client instead of authoring detections from scratch.

Enable and tune per client

Flip a rule on for one client, adjust its thresholds and add exceptions. Tuning is scoped per tenant, so quieting one client never blinds another.

Version-controlled content

Rule changes are tracked with full history and rollback. See what changed, when and why — and revert a bad tune in a single step.

Framework and ATT&CK mapping

Each detection is mapped to the frameworks it supports and the MITRE ATT&CK techniques it covers, turning your ruleset into an evidence-ready coverage map.

Tune with confidence

Adjust the noise without breaking the rule

Every practice has a client that needs a rule dialed differently. Do it safely — per tenant, tracked, and reversible.

Thresholds and exceptions

Raise a threshold, suppress a known-good source or add a client-specific exception — all without editing the shared rule content everyone else depends on.

Change history and rollback

Every enable, tune and disable is logged. Roll back to a previous version the moment a change turns out noisier than expected.

Coverage you can prove

See which ATT&CK techniques and framework controls your enabled rules cover — and where the gaps are — per client and across the fleet.

Why it fits

Fits how you already work

Detections don’t live in a separate console. They fire into the same queue, inherit sensible defaults and double as compliance evidence.

Detections feed the findings queue

A rule that fires becomes a finding in the same queue your team already triages — no separate alert console to babysit.

Multi-tenant defaults, per-client overrides

Set sensible defaults once, then override per client. New tenants inherit a known baseline instead of starting from a blank slate.

Mapped to 10 frameworks

The same detections that catch attacker behavior double as evidence toward the frameworks each client is working against.

No noisy out-of-the-box wall

Rules ship tuned to be actionable, not a firehose — so an enabled detection means something genuinely worth a tech’s time.

Part of one platform

One ruleset, every client, one platform

The Detection Rule Library is one piece of SBCMSP’s unified loop — detections fire into the same prioritized findings queue, get paired with guidance, map to your frameworks and re-verify on the next run.

  • KEV / EPSS-ranked severity
  • Version-controlled rule content
  • MITRE ATT&CK mapping
  • White-label client reporting
See the full platform
82
+27 pts
projected after top fixes

Run your first scan free

See a client’s real posture in minutes — then unlock all 1,692 checks.