Cybersecurity · free, no signup
Detection Rule Analyzer
Paste a detection rule and see what it will actually do once it is deployed — how it is anchored, what it will miss, and where it will fire on ordinary activity. A rule matching a single hardcoded path or hash is a rule an attacker defeats by renaming a file, and a rule with no time bound or no field constraint is one an analyst learns to close without reading. Every finding is derived from the rule text itself, so it is a statement about the logic rather than about a threat.
Authorized, defensive use only. Check assets you own or lawfully public data. This tool is educational and never provides another party's private data.
Paste a Sigma, YARA or KQL rule and see what it will actually do in production — how it is anchored, what it will miss, and where it will fire on ordinary activity. A rule matching one hardcoded path or hash is defeated by renaming a file; a rule with no field constraint is one an analyst learns to close without reading.
Every finding comes from the rule text itself. Nothing is executed, no data is queried, and no threat feed is consulted — so this is a statement about the logic, not about whether the behaviour it looks for is happening in your estate.
What happens to what you enter
- The analysis runs on Solvex servers. What is recorded afterwards is a SHA-256 hash of your input and a coarse summary of the outcome — never the input itself, and never a result you could be identified from.
- Tools that read public sources (certificate logs, DNS, a public chain) contact those sources from our servers through a fetcher that refuses private and internal addresses.
- An email address is stored only where a tool offers to send you a report and you choose to give one.
Limits: ten runs of this tool per minute from one address, and three signed reports per minute. Past that the tool says so and tells you when to try again.
When a free check is not enough
This tool reads what is public and reports what it can see. The SIEM-as-a-Service engagement is the authorized, specialist-led version: signed scope, findings proven by hand, a signed report, and a retest.
Explore SIEM-as-a-Service