DECTYL

The assessment · Free

How the assessment works.

← dectyl.io

01

Pick one attack scenarioTell us what matters to your business. Together, we agree a bounded set of detections and systems to assess.

02

Approve the inputsWe agree access and data handling first. Your team provides rule definitions, dependency inventories, and telemetry metadata through approved exports or read-only API access. No raw events, nothing installed for the assessment.

03

Review the findingsAfter collection and analysis, a 30-minute review covers the exposure, the evidence, and the next action. Bring your detection lead to verify findings in your environment.

04

Agree the next stepYou receive a summary for leadership and verification steps for your team. If broader work is useful, we scope a paid pilot together.

Illustrative

This detection cannot alert on shadow-copy deletion.

A rule intended to detect deletion of recovery copies is blocked by a missing dependency. The finding gives your team a way to confirm the exposure and repair the rule.

DECTYLAssessment · T1490 Inhibit System Recovery2026-09-25 09:00 UTC

Shadow Copy Deletion via vssadmin

Windows servers · app secops · owner svc_soc

CANNOT FIRE

The macro org_recovery_exclusions does not exist for this app and owner. Every result path requires it.

Verify
Parse the search as svc_soc in secops. Expected: undefined-macro error.
Suggested fix
Restore the intended macro in secops, or update the rule to the correct dependency. Recheck in the same app and owner context.
View the rule
index=endpoint EventCode=1 Image="*vssadmin.exe"
CommandLine="*delete*shadows*" `org_recovery_exclusions`

Fictional rule and scope. One of various failure modes Dectyl checks.

Each assessed rule gets a verdict: CAN FIRE CANNOT FIRE INDETERMINATE

CAN FIRE
The prerequisites covered by the assessment are verified for the stated scope and evidence window. This does not prove the rule will detect every attack or that an alert will reach an analyst.
CANNOT FIRE
A confirmed blocker prevents every relevant result path from producing an alert in the assessed scope. The finding includes the evidence and a check to verify it.
INDETERMINATE
Evidence is missing or inconclusive. The finding names what is needed to decide. A quiet log source alone does not prove a rule is broken.

Verify the fix. Then expand.

A paid pilot can cover more attack scenarios and recheck agreed findings after your team makes changes. We agree scope, success criteria, timing, and price before it starts.

For ongoing assessments, we agree the collection method and review cadence, then compare new evidence with the prior assessment to show what changed.

Share access and data handling details with your security team.

Get a free assessmentStart with your SIEM and the attack you care about.