Detection Content Generation and Improvement
Uncoder AI supports various tasks related to AI and non-AI detection content generation, summarization, and analysis.
Behavior Rule/Query Generation with AI and Custom Prompt AI Tasks
You can generate detection rules and queries for the following platforms:
Anomali Security Analytics
Apache Kafka ksqlDB
ArcSight
AWS Athena
AWS OpenSearch
Crowdstrike Endpoint Security
CSharp Regex
Datadog
Devo
DNIF
ElastAlert
Elastic Stack
Falco
Falcon LogScale
FireEye
FortiSIEM
Google SecOps
Graylog
HawkSearch
Hunters
IBM QRadar
Lacework
LimaCharlie
Logiq
Logpoint
LogRhythm
Microsoft Defender for Endpoint
Microsoft Sentinel
NVISO EE-Outliers
Palo Alto Cortex XDR
Palo Alto Cortex XSIAM
PowerShell
Qualys
Regex Grep
Roota
RSA NetWitness
Securonix
SentinelOne
Snowflake
Splunk
SQL
SQLite
STIX
StreamAlert
Sumo Logic
Sysmon
UberAgent ESA
VMware Carbon Black
Logsign Unified SecOps
Suricata
Tanium
Sophos EDR
Logz.io
Trend Micro XDR
Exabeam
IOC Query Generation
You can generate IOC queries for the following platforms:
ArcSight
AWS OpenSearch
Crowdstrike Endpoint Security
Elastic Stack
Falcon LogScale
FireEye
Google SecOps
Graylog
IBM QRadar
Logpoint
Microsoft Defender for Endpoint
Microsoft Sentinel
Qualys
RSA NetWitness
Securonix
SentinelOne
Snowflake
Splunk
Sumo Logic
VMware Carbon Black
Anomali
Apache Kafka ksqlDB
AWS Athena
Datadog
Devo
DNIF
Hunters
Sigma
SQL
SQLite
STIX
Short Summary, Full Summary, Decision Tree, and Query Optimization
You can generate short summaries, full summaries, and decision trees for the following platforms:
Anomali Security Analytics
Apache Kafka ksqlDB
ArcSight
AWS Athena
AWS OpenSearch
Crowdstrike Endpoint Security
CSharp Regex
Datadog
Devo
DNIF
ElastAlert
Elastic Stack
Falco
Falcon LogScale
FireEye
FortiSIEM
Google SecOps
Graylog
HawkSearch
Hunters
IBM QRadar
Lacework
LimaCharlie
Logiq
Logpoint
LogRhythm
Microsoft Defender for Endpoint
Microsoft Sentinel
NVISO EE-Outliers
Palo Alto Cortex XDR
Palo Alto Cortex XSIAM
PowerShell
Qualys
Regex Grep
Roota
RSA NetWitness
Securonix
SentinelOne
Snowflake
Splunk
SQL
SQLite
STIX
StreamAlert
Sumo Logic
Sysmon
UberAgent ESA
VMware Carbon Black
Note: Short summaries and full summaries can also be generated for texts in human language.
Validation
You can validate the syntax and structure for the following platforms:
Anomali Security Analytics
Apache Kafka ksqlDB
ArcSight
AWS Athena
AWS OpenSearch
Crowdstrike Endpoint Security
CSharp Regex
Datadog
Devo
DNIF
ElastAlert
Elastic Stack
Falco
Falcon LogScale
FireEye
FortiSIEM
Google SecOps
Graylog
HawkSearch
Hunters
IBM QRadar
Lacework
LimaCharlie
Logiq
Logpoint
LogRhythm
Microsoft Defender for Endpoint
Microsoft Sentinel
NVISO EE-Outliers
Palo Alto Cortex XDR
Palo Alto Cortex XSIAM
PowerShell
Qualys
Regex Grep
Roota
RSA NetWitness
Securonix
SentinelOne
Snowflake
Splunk
SQL
SQLite
STIX
StreamAlert
Sumo Logic
Sysmon
UberAgent ESA
VMware Carbon Black
Onum
Logsign Unified SecOps
Suricata
Tanium
Sophos EDR
Logz.io
Trend Micro XDR
Exabeam
Result Aggregation
You can aggregate query results for the following platforms:
IBM QRadar
Anomali
Athena
Elastic (EQL)
Falcon LogScale
Microsoft Defender for Endpoint
Microsoft Sentinel
Splunk
Sumo Logic
Detection Content Translation
Uncoder AI supports translations of several types:
Cross-platform translation (platform-native language to platform-native language)
Translation from a platform-agnostic language to a platform-specific one:
Sigma to platform-native language
Roota to platform-native language
Translation between different formats of the same platform
Remapping to OCSF
Cross-platform translation
The scope of support for each language is as follows:
Platform | Source | Target |
Anomali Security Analytics
| – | Basic detection logic |
AWS Athena:
| Basic detection logic | Basic detection logic |
AWS OpenSearch:
| Basic detection logic | Basic detection logic |
AWS OpenSearch:
| – | Basic detection logic |
CrowdStrike Endpoint Security:
| Basic detection logic | Basic detection logic |
ElastAlert:
| – | Basic detection logic |
Elastic Stack:
| Basic detection logic | Basic detection logic |
Elastic Stack:
| Basic detection logic | – |
Elastic Stack:
| – | Basic detection logic |
Falcon LogScale:
| Basic detection logic + Functions:
| Basic detection logic + Functions:
|
FortiSIEM
| – | Basic detection logic |
Google SecOps:
| Basic detection logic | Basic detection logic |
Graylog:
| – | Basic detection logic |
Hunters:
| – | Basic detection logic |
IBM QRadar:
| Basic detection logic + Functions:
| Basic detection logic |
IBM QRadar:
| Basic detection logic + Functions:
| – |
LogRhythm:
| – | Basic detection logic |
Microsoft Defender for Endpoint:
| Basic detection logic | Basic detection logic |
Microsoft Sentinel:
| Basic detection logic + Functions:
| Basic detection logic + Functions:
|
Microsoft Sentinel:
| Basic detection logic | – |
Palo Alto Cortex XDR
| – | Basic detection logic + Functions:
|
Palo Alto Cortex XSIAM
| – | Basic detection logic + Functions:
|
SentinelOne
| – | Basic detection logic |
Splunk:
| Basic detection logic (expressions and operators) + Functions:
| Basic detection logic + Functions:
|
Splunk:
| Basic detection logic | – |
Sigma rule | N/A | Basic detection logic |
VMware Carbon Black | Basic detection logic | Basic detection logic |
Translation from Sigma to platform-native language
You can translate from Sigma to the following languages:
Platform | Format and Data Schema |
Anomaly Security Analytics | Query:
|
Apache Kafka ksqlDB | Query (KSQL):
|
ArcSight | Query:
Rule:
|
AWS Athena | Query (SQL):
|
AWS OpenSearch | Query (Lucene)
Rule (JSON):
|
VMware Carbon Black | Query (Cloud):
Query (EDR):
|
Google SecOps | Query (UDM):
Rule (YARA-L):
|
Coralogix | Query
Alert
|
CrowdStrike Endpoint Security | Query (SPL):
|
CrowdStrike NextGen SIEM | Query:
|
CrowdStrike NextGen SIEM Falcon LogScale | Alert:
Query:
|
Devo | Query:
|
ElastAlert | Alert (Lucene):
Alert (DSL):
|
Elastic Stack | Detection Rule (EQL):
Detection Rule (Lucene):
ES|QL Detection Rule:
ES|QL Query
Kibana SavedSearch (JSON):
Kibana SavedSearch (NDJSON):
Query (DSL):
Query (EQL):
Query (Lucene):
Rule (Watcher):
|
FireEye | Query:
Rule (XML):
|
FortiSIEM | Rule:
|
Graylog | Query:
|
Hunters | Query:
|
LimaCharlie | Rule:
|
Logpoint | Query:
|
Microsoft Defender for Endpoint | Query (Kusto):
|
Microsoft Sentinel | Query (Kusto):
Rule (Kusto):
|
PowerShell | Query:
|
IBM QRadar | Query (AQL):
|
Qualys | IOC Query:
|
Palo Alto Cortex XDR | Query:
|
Palo Alto Cortex XSIAM | Query (XQL):
|
Regex Grep | Query:
|
RSA NetWitness | Query:
Query (EPL):
|
Roota | Rule:
|
Securonix | Query:
|
SentinelOne | PowerQuery:
Query (Events):
Query (Process State):
|
Snowflake | Query (SQL):
|
Splunk | Alert (SPL):
Query (SPL):
Query (XML):
|
Sumo Logic | Query (CSE):
Rule (CSE):
Query:
|
Sysmon | Config:
|
Trend Vision One | Query:
|
CSharp Regex | Query (LINQ):
|
Datadog | Query:
|
DNIF Query | Query:
|
HawkSearch | Query:
|
Lacework | Query:
|
Logiq | Rule:
|
LogRhythm | LR7 Query (Lucene):
Axon Query:
Axon Rule:
|
NVISO EE-Outliers | Query:
|
SQL | Query:
|
SQLite | Query:
|
STIX | Pattern:
|
StreamAlert | Alert:
|
UberAgent ESA | Query:
|
Translation from Roota to platform-native language
You can translate from Roota to the following languages:
Platform | Scope of support |
Anomali Security Analytics
| Basic detection logic |
AWS Athena:
| Basic detection logic |
AWS OpenSearch:
| Basic detection logic |
AWS OpenSearch:
| Basic detection logic |
CrowdStrike Endpoint Security:
| Basic detection logic |
ElastAlert:
| Basic detection logic |
Elastic Stack:
| Basic detection logic |
Elastic Stack:
| Basic detection logic |
Falcon LogScale:
| Basic detection logic + Functions:
|
FortiSIEM
| Basic detection logic |
Google SecOps:
| Basic detection logic |
Graylog:
| Basic detection logic |
Hunters:
| Basic detection logic |
IBM QRadar:
| Basic detection logic |
LogRhythm:
| Basic detection logic |
Microsoft Defender for Endpoint:
| Basic detection logic |
Microsoft Sentinel:
| Basic detection logic + Functions:
|
Palo Alto Cortex XDR
| Basic detection logic + Functions:
|
Palo Alto Cortex XSIAM
| Basic detection logic + Functions:
|
SentinelOne
| Basic detection logic |
Splunk:
| Basic detection logic + Functions:
|
Sigma rule | Basic detection logic |
Translation between different formats of the same platform
Translating between different formats of the lame platform (does not require the reverse translations balance):
AWS OpenSearch:
Query (Lucene) with ECS data schema → Rule (JSON) with ECS data schema
Google SecOps:
Query (UDM) with UDM data schema ↔ Rule (YARA-L) with UDM data schema
Elastic Stack:
Query (Lucene) with ECS data schema ↔ Detection Rule (Lucene) with ECS data schema
Query (Lucene) with ECS data schema → Rule (Watcher) with ECS data schema
Query (Lucene) with ECS data schema → Kibana SavedSearch (JSON) with ECS data schema
Detection Rule (Lucene) with ECS data schema → Rule (Watcher) with ECS data schema
Detection Rule (Lucene) with ECS data schema → Kibana SavedSearch (JSON) with ECS data schema
Detection Rule (TOML) with ECS data schema → Detection Rule (Lucene) with ECS data schema
Detection Rule (TOML) with ECS data schema → Kibana SavedSearch (JSON) with ECS data schema
Detection Rule (TOML) with ECS data schema → Query (EQL) with ECS data schema
Detection Rule (TOML) with ECS data schema → Query (Lucene) with ECS data schema
Detection Rule (TOML) with ECS data schema → Rule (Watcher) with ECS data schema
Query (EQL) with ECS data schema ↔ Detection Rule (Lucene) with ECS data schema
Query (EQL) with ECS data schema → Kibana SavedSearch (JSON) with ECS data schema
Query (EQL) with ECS data schema ↔ Query (Lucene) with ECS data schema
Query (EQL) with ECS data schema → Rule (Watcher) with ECS data schema
Falcon LogScale:
Query with Default data schema ↔ Alert with Default data schema
Microsoft Sentinel:
Query (Kusto) with Default data schema ↔ Rule (Kusto) with Default data schema
Rule (YML) with Default data schema → Rule (Kusto) with Default data schema
Rule (YML) with Default data schema → Query (Kusto) with Default data schema
Splunk:
Query (SPL) with Default data schema ↔ Alert (SPL) with Default data schema
Alert (YML) with Default data schema → Alert (SPL) with Default data schema
Alert (YML) with Default data schema → Query (SPL) with Default data schema
Remapping to OCSF
The scope of supported formats is as follows:
AWS OpenSearch Query (Lucene): ECS to OCSF
AWS OpenSearch Rule (JSON): ECS to OCSF
Elastic Stack Detection Rule (Lucene): ECS to OCSF
Elastic Stack Query (Lucene): ECS to OCSF
Falcon LogScale Alert: Default to OCSF
Falcon LogScale Query: Default to OCSF
IBM QRadar Query (AQL): LEEF to OCSF
Snowflake Query (SQL): Default to OCSF
Splunk Alert (SPL): Default to OCSF
Splunk Query (SPL): Default to OCSF
Sumo Logic Query: Default to OCSF
