Paste a rule. Get an instant quality scorecard — false-positive risk, MITRE ATT&CK coverage, lint findings, and an AI-generated fix with a diff you can ship.
title: Suspicious PowerShell Download Cradle
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith: '\\powershell.exe'
CommandLine|contains:
- 'DownloadString'
- 'Invoke-WebRequest'
condition: selection
level: highDetection teams spend hours reviewing rule quality by hand. DetectionLint does it in seconds — and catches the patterns humans forget.
Broad-process-no-parent-filter, unanchored regex, mutually-exclusive conditions — we check the patterns that actually flood your SOC.
Every rule gets an FP risk score 0–10 with reasoning. "Matches powershell.exe without parent filter — expect heavy false positives."
Auto-extract technique tags from your rule. Cross-reference against coverage gaps in your detection inventory.
Click once. Get an improved version of your rule with a diff — addressing lint findings while preserving detection intent.
Curated Sigma, KQL, SPL, YARA-L, and EQL rules from trusted upstream repos — each pre-scored for quality. Fork into your library with one click.
Fails the PR when detection rule quality regresses. Ship detections like you ship code — with a real quality gate.
CI checks, public libraries, AI-assisted fixes — the modern detection engineer's working surface, in one tool.
You wouldn't merge a PR without ESLint. We bring the same rigor to Sigma, KQL, SPL, YARA-L, and EQL — automatic checks against the patterns that flood SOCs with false positives.
Every analysed rule comes back with an FP risk score 0–10 and human-readable reasoning. Catch the broad process_creation rule before it pages an analyst at 3am.
Auto-extract MITRE ATT&CK techniques from rule logic, then cross-reference your full library to see exactly where your coverage maps — and where it doesn't.
API, GitHub Action, public rule library, AI "Suggest fix". DetectionLint plugs into the way your detection engineers already ship — PRs, repos, CI.
Start free. Upgrade when you want AI-generated fixes or team features.
For learning & one-off checks.
Solo detection engineers.
Detection teams, 3+ people.
20+ engineers, compliance-heavy.
Start free. 20 analyses a month. No credit card. Upgrade when you want AI fixes or team features.