Write the attack, then write the rule that would have caught it
A detection without a matching attack is a guess. You want a model that will emit the process tree and the Sigma rule in the same sitting, so the test and the control share a story.
Detection engineers building content for SIEM, EDR and lakehouse detections.
Why the mainstream APIs fail here
Frontier APIs will draft a Splunk query and then refuse to show you the event it is meant to match, because that event looks like an attack. It is meant to. That is the job.
How Redline is used for this
Describe the TTP, ask for the event, ask for the rule, ask for the bypass, ask for the tighter rule. Cap the content-pipeline key so a batch job has a ceiling.
A working loop
- Start from a TTP, not from a blank query.
- Generate a positive example before the rule.
- Keep the bypass pass; that is how the rule gets better.
Prompts are not stored. A signed receipt of the hash comes back on every call, so you can prove later what Redline logged. Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.