The Academy is free // the war room is optional
DAEMONCORE // ACADEMY
ENTERPRISE SIEM & DETECTION RULE REPOSITORY

The Detection Arsenal

PRE-VALIDATED • ZERO BOILERPLATE • MULTI-SIEM

Open-source rule repositories flood security operations with noisy alerts from vulnerability scanners, SCCM, and backup agents. DaemonCore detection packs are engineered from real red team engagements and incident response post-mortems: fully tuned, multi-platform, and verified with Atomic Red Team test probes.

SENTINEL & DEFENDERARM Templates + KQL
SPLUNK ENTERPRISEsavedsearches.conf
FALCON LOGSCALELQL Saved Query JSON
VALIDATION PROBESAtomic Red Team CLI
VERIFIED DETECTION REPOSITORY // Q3 2026 BENCHMARKS

Production Detection Packs (Instant Procurement)

Pre-validated detection logic with enterprise false-positive tuning. Expense directly with credit card or procurement.

MOST POPULAR
18 PRODUCTION RULES7 ATT&CK TECHNIQUES

Ransomware Precursor & Ingress Defense Pack

Kill the chain before the encryptor executes.

$149$299ONE-TIME LICENSE

Includes lifetime updates for this pack & future tuning fixes.

SUPPORTED PLATFORMS:
SentinelSplunkLogScaleSysmon
BUY NOW ($149)
Instant fulfillment via LemonSqueezy (.ZIP)
ESSENTIAL IDENTITY
24 PRODUCTION RULES6 ATT&CK TECHNIQUES

Active Directory & Kerberos Identity Attacks

Detect credential escalation and golden ticket forgery.

$199$349ONE-TIME LICENSE

Includes lifetime updates for this pack & future tuning fixes.

SUPPORTED PLATFORMS:
SentinelSplunkLogScaleSysmon
BUY NOW ($199)
Instant fulfillment via LemonSqueezy (.ZIP)
MODERN ATTACK VECTOR
16 PRODUCTION RULES6 ATT&CK TECHNIQUES

Cloud Infrastructure & Okta Identity Abuse

Stop token theft, OAuth consent abuse, and IAM escalation.

$179$329ONE-TIME LICENSE

Includes lifetime updates for this pack & future tuning fixes.

SUPPORTED PLATFORMS:
SentinelSplunkLogScaleSysmon
BUY NOW ($179)
Instant fulfillment via LemonSqueezy (.ZIP)
FOR SOC LEADS, THREAT HUNTERS & MSSPs

Full-Spectrum Detection Engineering Feed (All-Access)

Continuous Threat Detection Pipeline for Enterprise SOCs & MSSPs. Continuous continuous integration feed with direct Git repository access, automated regression tests, quarterly APT rule drops, and team licensing.

Instant access to all current rule packs (Ransomware, Active Directory, Cloud Identity)
New rule packs & APT threat updates shipped quarterly for 12 months
Private GitHub repository sync access (direct git clone / CI/CD automation)
Ready-to-deploy ARM templates, Splunk conf files, and LogScale packages
$999$1499

BILLED ANNUALLY // UNLIMITED ANALYSTS

GET ALL-ACCESS PASS ($999/YR)Already subscribed? Set up GitHub repo access →

Includes automated invoice, receipt for expense reports, and W-9 support.

LIVE RULE INSPECTOR: UNREDACTED PRODUCTION LOGIC

Inspecting active pack: Ransomware Precursor & Ingress Defense Pack

SELECT RULE:
Volume Shadow Copy Destruction (Ransomware Precursor)T1490Impactcritical SEVERITY
Included in Ransomware Precursor & Ingress Defense Pack

Detects execution of vssadmin.exe, wmic.exe, wbadmin.exe, or PowerShell commands to purge volume shadow copies or backup catalogs prior to ransomware payload detonation.

DeviceProcessEvents
| where TimeGenerated >= ago(1h)
| where (FileName in~ ("vssadmin.exe", "wmic.exe", "wbadmin.exe", "vssvc.exe") or InitiatingProcessFileName in~ ("vssadmin.exe", "wmic.exe"))
| where ProcessCommandLine has_any ("delete shadows", "shadowcopy delete", "catalog -quiet", "resize shadowstorage")
| extend ParentProcess = InitiatingProcessFileName, Host = DeviceName, Operator = AccountName
| project TimeGenerated, Host, Operator, FileName, ProcessCommandLine, ParentProcess
| sort by TimeGenerated desc
BUILT FOR PRACTITIONERS

Why Standard Rule Repositories Fail in Real SOCs

PROBLEM: Alert Fatigue & Spam

Untuned Open-Source Sigma

Generic GitHub rules trigger hundreds of times a day on SCCM, Nessus, Qualys, and Tanium, burning out analysts until the rule is disabled.

✓ DaemonCore packs include hardened enterprise regex exclusion baselines.
PROBLEM: High Friction Deployment

Manual Rewrite Across Dialects

Engineers spend days converting logic between Splunk SPL, Sentinel KQL, and Falcon LogScale LQL, frequently introducing subtle syntax bugs.

✓ Shipped with drop-in native ARM templates, conf stanzas, and LQL queries.
PROBLEM: Blind Trust

Untested Blindspots

Most organizations have no way of knowing if an alert will actually fire when an adversary breaches the perimeter.

✓ Every rule is paired with an Atomic Red Team one-liner and test payload.