CISO dinner in Vancouver, Sept 9RSVP
Alaris
Pricing

Detection rules built for your environment.

AI-assisted rule creation, tuning, and ATT&CK coverage mapping for your unique stack.

Custom Rule Builder

Detection logic tailored to your stack

Describe a threat in plain language or import an advisory. Alaris turns it into tested, platform-specific detection logic for your stack.

Create a new detection
Describe a threat
Import from URL
ContextAutofill All Fields
Detection name
e.g. SSH Brute Force Detection
Severity
Critical
High
Medium
Governed Change Requests

Every rule change requires human approval

Whether a rule is created by an analyst or proposed by an Alaris agent, it follows the same change request process. Automated checks run first; a reviewer then approves it or requests edits before anything reaches production.

Opendraft/rule/T1566-phishmain
Detect O365 credential harvesting
Proposed by Alaris Agent
Checks 5/6
Reviewers
KS
AM
Merge blocked, 1 approval requiredRequest changesApprove
a4f2c91Tune threshold, cut FP rate 62%KS2h
7b3e08dRoll back to v1.2.1 after driftREVERTAM1d
c902a8aAdd O365 credential-harvest logicKS3d
Detection Inventory

See every rule and its production status

Manage your full detection library in one place. Track lifecycle, severity, source, MITRE mapping, compiled rules, and deployment status across every connected security platform.

Detection inventory25 totalAll rules · every target
21Deployed
4Warning
0Stale
0Failed
NameLifecycleSeverityMITRERules
Suspicious PowerShell ExecutionDeployedHighT1059.0012
New Service InstallationDeployedHighT1543.0031
Lateral Movement via WMIWarningCriticalT10472
Registry Run Key PersistenceDeployedMediumT1547.0012
MITRE ATT&CK Mapping

Know exactly what you cover and what is missing

See which ATT&CK tactics and techniques your current rules cover, where blind spots remain, and which gaps matter most for the threats targeting your environment.

Tactics: 12 / 14Techniques: 38 / 852Detections: 25 3+ detections Authored
Reconnaissance
7
T1589 Victim Info
T1590 Networks
T1591 Organization
T1593 Open Sites
T1594 Victim Sites
T1595 Active Scan
T1596 Open Data
Resource Dev.
6
T1583 Infrastructure
T1584 Compromise
T1585 Accounts
T1586 Accounts
T1587 Capabilities
T1588 Capabilities
Initial Access
7
T1078 Valid Accounts
T1091 Replication
T1133 External Service
T1189 Drive-by
T1190 Exploit Public
T1195 Supply Chain
T1566 Phishing
Execution
8
T1047 WMI
T1053 Scheduled Task
T1059 Command Shell
T1072 Software Deploy
T1106 Native API
T1129 Shared Modules
T1204 User Execution
T1569 System Services
Persistence
9
T1037 Logon Script
T1053 Scheduled Task
T1078 Valid Accounts
T1098 Account Manip.
T1133 External Service
T1136 Create Account
T1176 Browser Ext.
T1197 BITS Jobs
T1543 Create Service
Privilege Esc.
9
T1037 Logon Script
T1053 Scheduled Task
T1055 Process Inject
T1068 Exploitation
T1078 Valid Accounts
T1098 Account Manip.
T1134 Access Token
T1484 Domain Policy
T1547 Boot Logon
Defense Evasion
12
T1006 Direct Volume
T1014 Rootkit
T1027 Obfuscated
T1036 Masquerading
T1055 Process Inject
T1070 Clear Events
T1078 Valid Accounts
T1112 Modify Registry
T1127 Trusted Dev.
T1134 Access Token
T1140 Deobfuscate
T1197 BITS Jobs
Credential Access
9
T1003 OS Credential
T1040 Network Sniff
T1056 Input Capture
T1110 Brute Force
T1111 MFA Intercept
T1187 Forced Auth
T1212 Exploitation
T1528 Steal Token
T1539 Web Session
Discovery
9
T1007 System Service
T1010 App Window
T1012 Query Registry
T1016 Network Config
T1018 Remote System
T1033 System Owner
T1046 Network Scan
T1049 System Network
T1057 Process Discovery
Lateral Movement
8
T1021 Remote Service
T1072 Software Deploy
T1080 Taint Content
T1091 Replication
T1210 Exploitation
T1534 Internal Phish
T1550 Alternate Auth
T1563 Remote Service
Collection
9
T1005 Local Data
T1025 Removable
T1039 Network Share
T1056 Input Capture
T1074 Data Staged
T1113 Screen Capture
T1114 Email
T1115 Clipboard
T1119 Automated
Command & Control
8
T1071 App Protocol
T1090 Proxy
T1092 Comm Device
T1102 Web Service
T1104 Multi-Stage
T1105 Ingress Tool
T1132 Data Encoding
T1219 Remote Access
Continuous Rule Optimization

Your detections improve with every investigation

Alert triage and threat hunting teach Alaris what your environment needs. Agents propose new, tuned, consolidated, or retired rules. Each proposal is routed through human review.

Continuous learning loopAlways on
Alert triage
Outcomes + noise
Rule intelligence
Learns your environment
Threat hunting
Findings + gaps
Autonomous proposalsSent through change requests
AddOkta MFA fatigueOpen CR
TuneImpossible travel thresholdOpen CR
Merge6 duplicate Sigma rulesOpen CR
RetireLegacy PowerShell v1Open CR

Find out exactly which attacks you can't detect