Bring the logs
Review Sysmon process creation or Windows scheduled task creation events as JSON.
FIRST PRODUCT / WINDOWS + SPLUNK
Detection Workspace builds a repeatable foundation for detection design, starting with Windows logs. The first usable step: local log review and SPL drafting.
This version does not connect to Claude. Logs remain in your browser; the generated SPL is a template-based starting point.
Open workspaceReview Sysmon process creation or Windows scheduled task creation events as JSON.
Identify missing host, timestamp, user and process fields.
Generate a template for the selected event profile and map it to your Splunk schema.
Test with positive, negative and incomplete data. A draft is not an automatic threat verdict.
Detectonic brings security data analysis and detection design together. Windows and Splunk are our first focus. SOC and DFIR are the next steps in the same approach.
In-browser JSON log review, field checks and template-based SPL drafting.
Claude assistance, evaluation with test data, then SOC / DFIR workflows.
Roadmap ↗