Versioned guidance for developers, detection engineers, researchers and SOC teams. Claims are anchored to the v0.4.0 engine repository.
Understand the product and run the reference engine locally.
OpenSet up the Python engine, API and dashboard.
OpenConfigure authentication, tenancy, persistence and operational boundaries.
OpenWork with stable detection IDs, versions and ATT&CK mappings.
OpenUse the health, readiness, version and detection service boundaries.
OpenConnect JSON, SIEM, Sigma, STIX and FusionOps outputs.
OpenMove from local development to a hardened production boundary.
OpenUnderstand authentication, tenancy, supply-chain and assurance boundaries.
OpenKeep the core pipeline, repository map and operational vocabulary close at hand.
OpenIf implementation and documentation ever disagree, inspect the engine repository and update this documentation rather than inventing behavior.