NEWNightwatch is live. Autonomous hunting and detection engineering. See how it works See how it works →
Back

🌙 Nightwatch is live in detections.ai Enterprise.

Robert Fly

Written by Robert Fly · CEO & Founder

🌙 Nightwatch is live in detections.ai Enterprise.
Share on social
September 15, 20263 minute read


When new threat research lands, two questions get asked immediately:

Are we impacted? Are we covered?

Answering them means pulling apart the research, figuring out which behaviors matter to your environment, checking existing detections, and writing and running hunts. On top of that there’s tuning, testing, deploying and monitoring deployed detections.

That’s A LOT of work for one report and when you finish, there’s probably 5 more reports waiting for you.

We built Nightwatch to do this work automatically.

It Starts With Your Environment + Detections

When you connect Nightwatch, it builds an understanding of your environment and the detections you already run. That context helps it identify relevant research, analyze detection opportunities, hunt for evidence of impact, and draft detections for the gaps.

It remembers your environment, your detections, and your preferences, and updates that memory as it learns.

The coverage check is super important. Finding a rule mapped to the same ATT&CK technique is useful for boss reports. But, you still need to know whether its logic catches the behavior described in the report.

Does it look for the right command? Does it use data you collect? Would an exclusion filter out the activity you’re investigating?

Nightwatch compares the behavioral attack chain with what your team actually runs.

The Hunt Is On 🔍

Based on those same behaviors, Nightwatch will kick off a hunt across your stack. Depending on what it finds it may tune the query, or expand the search. It reasons over the findings using both the approach the attacker took and alternative approaches they could take in the future.

We show you all the queries we ran, what it returned, and our reasoning behind the findings. That gives you something concrete to investigate.

We make it easy to automate future hunts for the same threats. You may not see the adversary today, but we’ll scan your environment on the frequency you choose.

The detections it drafts use your team’s conventions: data models, naming, exclusions, and the fields your existing detections rely on. Your team reviews the logic and approves deployment.

A Completely Hypothetical, Would Never Happen Example

Imagine a world where there’s a SharePoint vulnerability, some new research describes an initial exploit request followed by web shell activity. You run SharePoint on premises and collect IIS logs.

Your existing detections cover the web shell behavior. But you don’t have coverage for the initial request described in the research.

That’s a useful distinction. You have coverage for part of the attack chain, and a specific gap to investigate.

This is the work Nightwatch takes on: inferring the impact of the intel on your environment, checking the reported behavior against your library, hunting the relevant telemetry, and drafting a detection for the uncovered behavior. You can inspect the request conditions, the fields used, the hunt results, and whether the proposed exclusions make sense.

That work is on a platter, ready for you to take the next steps.

Time Saved & Deeper Work

We’ve previewed this in customer hands and I’m amazed by how well it does.

The research analysis time it saves is hours. Add the coverage checks, detection writing, tuning, threat hunting, etc and you’ve saved days or weeks of work.

And while the time saving is huge, even more important is the acceleration of throughput I’ve seen it enable. Teams are able to get to research, coverage and hunts they never would have before.

It’s incredibly exciting to put this in more people’s hands!

Book a walkthrough to dive deeper into Nightwatch and it’s capabilities: https://meetings-na2.hubspot.com/robert-fly?uuid=a06b82b6-231e-4037-bc5b-f09707955c21

Read more

Subscribe

Stay connected

Join the community that moves faster than the threat.

Subscribe to our newsletter