Detection assessment · Read-only
Your detection coverage is a mirage. Dectyl shows what’s real.
Find the detections that can no longer alert on the attacks you care about, with evidence your team can verify and a suggested fix.
Enabled doesn’t mean able to alert.
Windows events switch to XML. Logs keep arriving in the SIEM.
The rule still filters on the previous source format and depends on its fields.
The rule stays enabled. Its assumptions about the data have changed.
If no event can satisfy the required filter, the rule cannot alert.
An illustrative failure mode. Dectyl checks source and field evidence to confirm the mismatch, or names the evidence still needed.
Your environment changes. Does your coverage hold?
- SIEM migration
- Add-on or parser upgrade
- Log sources cut to save cost
- MDR handoff
- A board or risk review that needs evidence behind the coverage claim
Start with one attack scenario.
Tell us your SIEM and the attack you care about. We agree which detections and systems to assess.
Your team shares approved exports or authorizes read-only API access. No raw events.
Join a 30-minute findings review: the exposure, the evidence, and the next action.
The review follows input collection and analysis. A clear summary, with checks your detection team can run.
Send your SIEM and the attack you care about.
Security questions? Where it runs →