For security teams

Equip your SOC with DFIR reference your analysts will actually open.

The time between “something is wrong” and “we know what to collect” is where most of an incident’s response time goes, and it is spent re-deriving things somebody already worked out. This is that work, written down: collection orders, artifact references with hunting queries, and detection rules that arrive with their false-positive budgets already measured.

Compare every plan

€29/seat/mo · minimum 3 seats, so from €87/mo · no card charged during the trial

What a team licence adds

Centralised billing

One invoice, one card, one renewal date, and a VAT receipt that a finance team will accept without a conversation. Analysts never expense it individually and nobody loses access because a personal card expired.

Raw rule packs

Sigma, YARA and Snort as dated packs under CC0, with the false-positive notes that decide whether a rule survives its first fortnight. Public domain, so deploying them into your SIEM or shipping them inside your own product needs no licence review.

Seat management

Invite an analyst by email, see who has accepted, and revoke a seat the day somebody leaves. Team plans also carry API keys for pulling the threat feed into your own tooling on a schedule.

What every artifact here goes through first

Detonated, not described

Run on an isolated Windows 11 machine and diffed against a clean snapshot.

Versioned

Every artifact carries the build it was observed on, because artifacts move between builds.

Corrected in public

When a later build changes something, the page is fixed and the change is recorded in the ledger.

How we verify →

Team

Corporate security teams, MSSPs, consultancies

€29/seat/mo€45/seat/mo

Minimum 3 seats, so from €87/mo

  • Everything in Pro, for every seat
  • Seat management from 3 seats up
  • Raw Sigma, YARA and Snort rule packs
  • Threat Wire export, JSON, CSV and STIX 2.1
  • Scoped, revocable API keys for your own tooling
  • One invoice, and a record of who had access when

Seats are managed from the team console as soon as checkout completes.

Expense it

Convince your boss

Most people who want this have a corporate card and no appetite for writing the justification. Here it is, written. Change what is wrong about your team and send it.

Subject: Subscription request: Security Artifacts (DFIR reference and detection rules)

Hi,

I would like to expense a subscription to Security Artifacts, a DFIR reference and detection-engineering publication. It is €9/mo for an individual licence, or €29/seat/mo with a minimum of 3 seats for the team plan.

What it gives us:

- Detection rule packs (Sigma, YARA, Snort) released under CC0, so we can deploy them into our SIEM, modify them, and keep them with no licence review. Each rule ships with measured false-positive notes, which is the part that usually costs us a week of tuning.
- First-hour incident playbooks and one-page triage sheets covering the collection order for Windows, Active Directory and cloud identity cases. These reduce the time between "something is wrong" and "we know what to collect", which is where most of our MTTR actually goes.
- An artifact reference with hunting queries in Splunk SPL, Sentinel KQL and Elastic EQL, so a question about what an artifact proves does not become an afternoon of research.
- A threat wire tracking CISA KEV additions with their federal remediation deadlines, which is directly useful for our own patch prioritisation.

Everything published is verified on an isolated analysis machine before release rather than summarised from vendor reporting, which is the reason I am asking for this one specifically rather than a general research budget.

The team plan also gives us centralised billing, seat management, and API access for pulling the threat feed into our own tooling.

Happy to trial it first and report back on whether it earns its place.

Thanks,