DECTYL

Detection assessment · Read-only

Your detection coverage is a mirage. Dectyl shows what’s real.

Find the detections that can no longer alert on the attacks you care about, with evidence your team can verify and a suggested fix.

Illustrative scenario

Enabled doesn’t mean able to alert.

The source changesXML

Windows events switch to XML. Logs keep arriving in the SIEM.

The rule expectsOld format

The rule still filters on the previous source format and depends on its fields.

The status saysEnabled

The rule stays enabled. Its assumptions about the data have changed.

The consequenceNo matching data

If no event can satisfy the required filter, the rule cannot alert.

An illustrative failure mode. Dectyl checks source and field evidence to confirm the mismatch, or names the evidence still needed.

See a finding your team can verify →

Your environment changes. Does your coverage hold?

  • SIEM migration
  • Add-on or parser upgrade
  • Log sources cut to save cost
  • MDR handoff
  • A board or risk review that needs evidence behind the coverage claim
Free

Start with one attack scenario.

01

Tell us your SIEM and the attack you care about. We agree which detections and systems to assess.

02

Your team shares approved exports or authorizes read-only API access. No raw events.

03

Join a 30-minute findings review: the exposure, the evidence, and the next action.

The review follows input collection and analysis. A clear summary, with checks your detection team can run.

Send your SIEM and the attack you care about.

Founder-run