Skip to main content

Overview

Wirespeed imports custom detection rules from supported security platforms. You can review and categorize these rules in one place. When an imported rule fires, Wirespeed applies its category and starts the standard detection workflow.

How It Works

  1. Automatic Sync: Wirespeed periodically syncs custom detection rules from connected EDR, XDR, and SIEM providers.
  2. AI Classification: Wirespeed AI suggests a detection category from the rule content and behavior.
  3. Rule Review: You can review the rule, change its category, and configure Always Notify.
  4. Automatic Matching: When the rule fires in the provider, Wirespeed matches the alert to the imported rule and applies its category.

Supported Integrations

The following integrations support automatic custom detection import:
  • CrowdStrike: Imports custom Indicator of Attack (IOA) rules
  • Google Chronicle: Imports custom detection rules
  • Microsoft Defender: Imports custom detection rules from Microsoft 365 Defender and Microsoft Sentinel
  • Palo Alto Cortex: Imports custom detection rules
  • SentinelOne: Imports custom detection rules
More integrations are being added regularly. Check your integration’s documentation page for the latest capabilities.

Manage Off-Platform Detections

Go to Settings > Detection Rules > Off-Platform Detections to review rules synced from your integrations.

View Imported Rules

The Off-Platform Detections tab shows the rules imported from your providers:
  • View detection name, description, and severity
  • See which integration each rule comes from
  • Check whether the rule is enabled in the provider
  • Review the selected and AI-suggested categories

Review Rules

Open a rule to review its details and sample detection. You can use the AI-suggested category or select a different category.
Wirespeed AI suggests a category from the rule’s indicators, behaviors, and threat patterns. Select a different category if the suggestion does not match your workflow.

Rule Details

When reviewing or editing an imported rule, you can view:
  • Detection Information: Name, description, severity, and source payload
  • Categorization: Selected category and AI suggestion (if available)
  • Sample Detection: An example of what this rule detects (when available from the provider)
  • Provider Metadata: Additional context from your security platform
  • Raw Payload: Full JSON structure of the rule as received from the integration

Provider Status and Always Notify

  • Enabled in Provider: Shows whether the rule is enabled in the source platform. This value is read-only in Wirespeed.
  • Always Notify: Keeps detections from this rule open for review, regardless of the normal verdict result.
To enable or disable a rule, use the source provider. Wirespeed does not change this provider setting.

Detection Matching

When a detection is received from an integrated platform:
  1. Wirespeed checks if it matches an imported custom detection rule
  2. Wirespeed uses a match when the provider rule is enabled and has a selected or AI-suggested category
  3. Wirespeed applies the category and starts the normal verdicting and case creation workflow
  4. The detection timeline logs show that it was matched to an imported rule
Wirespeed matches rules by integration and provider rule ID. Deleted rules and rules disabled in the provider do not match.

Best Practices

  1. Review Regularly: Check for rules that were recently synced from your security platforms.
  2. Review AI Suggestions: Confirm that each suggested category matches your team’s workflow.
  3. Use Sample Detections: Review sample detections when available to understand what the rule detects.
  4. Monitor Provider Status: Check rules that are disabled in the provider.
  • Custom Detections - Create custom detections using Wirespeed’s query language
  • Advanced Queries - Learn how to query events in Wirespeed’s SIEM
  • Verdicts - Understand how detections are automatically processed and escalated