Log Lens · v1.0 · production

Detection engineering, accelerated.

Describe a threat in plain language. Log Lens maps it to MITRE ATT&CK techniques, identifies the required log sources, and generates SIEM-agnostic detection logic ready for review. The work stays yours — the toil doesn't.

$ log-lens analyze --ttp "credential dumping"

mapping to MITRE ATT&CK...
T1003.001 — LSASS Memory
T1003.002 — Security Account Manager
T1003.003 — NTDS

required log sources:
Windows Security Event Log (4624, 4648)
Sysmon (Process Create, ProcessAccess)
PowerShell Script Block Logging

3 techniques mapped · 3 log sources identified
$ _
T1003 — Credential dumping T1021 — Remote services T1059 — Command interpreter T1078 — Valid accounts T1486 — Data encrypted for impact T1566 — Phishing T1003 — Credential dumping T1021 — Remote services T1059 — Command interpreter T1078 — Valid accounts T1486 — Data encrypted for impact T1566 — Phishing

Six things Log Lens does, exceptionally well.

01

Natural language to ATT&CK

Describe an adversary behavior in plain English. Log Lens returns the matching technique IDs, sub-techniques, and tactic context — with confidence scoring and rationale.

02

Log source identification

For every mapped technique, get the specific log sources, event IDs, and telemetry channels required to detect it. Including provider-specific guidance (Sysmon, EDR, cloud).

03

SIEM-agnostic detection logic

Generate detection rules in Sigma, KQL, SPL, or LogScale syntax. Translate between formats. Export to your platform without rewrite cycles or vendor lock-in.

04

Coverage heatmap

Visualize your current detection coverage across the ATT&CK matrix. Identify gaps by tactic, technique, or threat actor relevance to your industry profile.

05

Industry threat profiles

Composite scoring tuned to your sector — Insurance, Banking, Healthcare, Technology, Hospitality, Retail. CISA KEV, ATT&CK Groups, and ThreatFox signal fused.

06

Exportable libraries

Detection rules export as version-controllable artifacts. Plug into your detection-as-code pipeline. Reviewable diffs, no opaque platform state.

From threat to detection, in three steps.

01 / Describe

Plain language in.

"Detect credential dumping on domain controllers." "Find lateral movement via WMI." "Catch Kerberoasting attempts in our environment." No syntax to learn. No taxonomy to memorize.

02 / Review

Transparent mapping.

Log Lens shows the ATT&CK techniques it matched, the rationale behind each match, the log sources required, and the confidence score. You decide what's right for your environment.

03 / Export

Detection logic out.

Generated rules in your SIEM's native syntax — Sigma, KQL, SPL, LogScale. Copy to your IDE. Commit to your detection-as-code repo. Iterate. Ship.

04 / Refine

Continuous evolution.

New ATT&CK techniques and log sources are added as the framework evolves. ThreatFox and CISA KEV signals feed background scoring. Your library stays current without manual upkeep.

Start free. Scale when it matters.

Free

$0/month
  • 10 analyses per month
  • Natural language to ATT&CK
  • Log source identification
  • Sigma rule export
  • No coverage heatmap
  • No industry threat profiles
Start free

Team

$199/month
  • Everything in Pro
  • Up to 10 seats
  • Shared detection libraries
  • SSO / SAML
  • API access
  • Priority support
Contact sales

Enterprise plans with custom seat counts, self-hosted deployment, and compliance attestations available. Talk to us →

Stop writing detections from scratch.

Try Log Lens free. 10 analyses per month, no credit card, no demo call required.