5 min read
Detections as YAML, and why we show you every rule
Black-box scoring is hard to trust and impossible to audit. Every Wardell detection is a file you can read.
Sam Whitaker
Detection engineer

If you cannot read a rule, you cannot tell an auditor why it fired, or why it did not.
A rule is a file
Every one of our 312 managed detections is plain YAML: the sources it reads, the sequence it looks for, the time window, and what suppresses it. You can open it, copy it and change it.
Test before you trust
Before any change goes live, run it against the last 30 days. You see every match and what it became. Most teams write their first custom rule in week two.
Send us one week of logs. We send back what we found.
Connect one source with a read-only key. Within 48 hours you get a written report of what Wardell would have caught. No contract, and you can disconnect at any time.