FIRST PRODUCT / WINDOWS + SPLUNK

Better queries.
Clearer evidence.

Detection Workspace builds a repeatable foundation for detection design, starting with Windows logs. The first usable step: local log review and SPL drafting.

From an observation
to a reviewable draft.

This version does not connect to Claude. Logs remain in your browser; the generated SPL is a template-based starting point.

Open workspace
01

Bring the logs

Review Sysmon process creation or Windows scheduled task creation events as JSON.

02

Check the fields

Identify missing host, timestamp, user and process fields.

03

Build an SPL draft

Generate a template for the selected event profile and map it to your Splunk schema.

04

Validate with a human

Test with positive, negative and incomplete data. A draft is not an automatic threat verdict.

A small starting point.
A clear direction.

Detectonic brings security data analysis and detection design together. Windows and Splunk are our first focus. SOC and DFIR are the next steps in the same approach.

Available today

JSON → SPL

In-browser JSON log review, field checks and template-based SPL drafting.

Development direction

Claude + validation

Claude assistance, evaluation with test data, then SOC / DFIR workflows.

Roadmap ↗