TFTHREATFADE
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
GitHub
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
Docsv0.4.0
Getting startedInstallationConfigurationDetection packsAPIIntegrationsDeploymentSecurityReference
Developer documentation

Build with the actual engine.

Versioned guidance for developers, detection engineers, researchers and SOC teams. Claims are anchored to the v0.4.0 engine repository.

v0.4.0

Getting started

Understand the product and run the reference engine locally.

Open

Installation

Set up the Python engine, API and dashboard.

Open

Configuration

Configure authentication, tenancy, persistence and operational boundaries.

Open

Detection packs

Work with stable detection IDs, versions and ATT&CK mappings.

Open

API

Use the health, readiness, version and detection service boundaries.

Open

Integrations

Connect JSON, SIEM, Sigma, STIX and FusionOps outputs.

Open

Deployment

Move from local development to a hardened production boundary.

Open

Security

Understand authentication, tenancy, supply-chain and assurance boundaries.

Open

Reference

Keep the core pipeline, repository map and operational vocabulary close at hand.

Open
Source of truth

If implementation and documentation ever disagree, inspect the engine repository and update this documentation rather than inventing behavior.