Free Tool

Detection Engineering Cycle Template
twelve sections that turn ad hoc detection rule writing into a defensible operating cycle

A free, copy-ready detection engineering cycle template. Twelve structured sections covering cycle header and version control, cycle charter and scope and authority, threat model input and ATT&CK technique scope across four input streams, log source coverage check and ingestion fitness assessment, rule lifecycle plan with write and tune and retire and carry-forward decisions, validation pattern with purple-team and BAS and red-team after-action handoff, false-positive triage backlog and noise budget, detection content register and platform target stack, ten cycle metrics for the quarterly governance review, operating cadence with calendar and event-driven triggers, cross-team handoff with SOC and AppSec and VM and IR and CTI, and cycle governance with sign-off and template revision. Aligned with NIST CSF 2.0 DE.CM and DE.AE, NIST SP 800-53 SI-4 and AU-2 and AU-6 and SI-2, SOC 2 CC7.2 and CC7.3, ISO 27001 Annex A 8.16 and A 8.15 and A 5.30, PCI DSS Requirement 10 and 12.10, NIS2 Article 21(2), DORA Article 6 and 9 and 17. Built for detection engineering leads, SOC managers, security operations leaders, security engineering teams, AppSec leads, vulnerability management leads, incident response leads, threat intelligence programme leads, GRC and compliance teams, CISOs, security architects, audit committees, and board risk committees that need a defensible alternative to ad hoc rule writing against whichever alert produced the most noise that week.

No credit card required. Free plan available forever.

Loading tool...

Run the detection engineering cycle on the live workspace, not on a side spreadsheet

SecPortal pairs every cycle to a versioned engagement record so the in-scope technique register, the log source coverage record, the rule lifecycle plan, the validation evidence, the false-positive backlog, the cycle metrics, the cross-team handoff record, and the framework anchor all live on one workspace with named-actor activity log. Free plan available.

No credit card required. Free plan available forever.