This month's Nebulog covers new features and expansions to the platform. To improve detection workflows, we added full version history to detections, persistent reference tables, and published GATES, a new open source methodology for deciding when a hunt should become a standing detection. In addition, we introduced our first set of user roles to expand governance, risk and compliance (GRC) capabilities for Nebulock administrators.
Detection Versioning Detections now show version history and change impact summaries.
Detection Versioning now logs a full version history capturing the full state of the environment at creation: logic, MITRE mappings, severity, and metadata. Revert to any previous version without losing history, since the versions in between stay on record.
These new capabilities help users understand when and why changes were made to improve tuning, reduce repeat mistakes, and encourage more experimentation.
On every detection, users now have access to:
Journal tab: A timeline showing every version of a detection Compare tab:Side-by-side diff comparing any two versions to see exactly what moved AI-generated Summary and Change Impact assessment explaining what an edit does to detection behavior This brings the Govern and Evolve stages of ADEF's FORGE lifecycle into the platform itself. Detection Versioning is live today, and existing rules start versioning automatically from your next save.
Reference Tables for Detection Engineering Create or use pre-built reference tables for detections Nebulock now provides Reference Tables to improve detection rule workflows. Instead of hard coding values and maintaining multiple lists, reference tables allow users to define a list once and reference it across multiple detections. Every rule that uses it inherits updated changes immediately, reducing duplication errors and workflow interruptions.
Users can create their own, or use pre-built tables maintained by Nebulock’s Detection Engineering and Threat Hunting (DE/TH) team.
What's Available:
14 pre-built threat intelligence tables: Battle-tested intel that powers Nebulock’s own detections and is organized by attacker techniques: credential theft tools, exfiltration utilities, tunneling software, discovery commands, destruction tools, third-party RMM tools, URL shorteners, LOLBins, and script hosts.Custom reference tables: Use it for organizational context, such as IP, users, sensitive hosts, approved domains, or any allowlist/denylist your environment needs. Add entries one at a time or bulk import via CSV upload.Releasing in the next few days, Reference Tables will be available to all users in the Detections page.
The GATES Method for Detection Engineering The GATES method is a five-step checklist to graduate findings into detections, We added a new open source tool with the publishing of the GATES Method , an approach to help the detection engineering and threat hunting community determine when a threat hunt should graduate to a standing detection. The determination can happen with a short mental checklist or executed by agents in an engineering loop. The reasoning automatically compounds over time, improving detections while preventing teams from starting from zero.
The GATES Method asks five questions:
Generalizable: a repeatable behavior, or a one-off?Additive: does it fill a real gap in your coverage?Tunable: can you tell the attack apart from normal activity?Exposure-tested: did you cover the ways it can be bypassed?Sustainable: can you reliably see it, and is the upkeep worth the risk?Clearing all five earns a standing detection. Miss one, and GATES routes it somewhere useful.
We’ve open sourced this method, shipping as a /skill with worked examples in the ATHF repo .
Role-Based Access Controls Assign roles scoped to user access with role-based access controls. Nebulock now has role-based access controls (RBAC) for administrators to assign different levels of platform access to their users. This allows GRC teams to enforce governance policies and reduce unintended access to sensitive information. For added flexibility, enforcement is available via the UI or API.
Our first RBAC release introduces three roles:
Platform User for threat hunters and detection engineers. Run hunts, investigate findings, and tune detections, with full access to threat intelligence and detection workflows.Organization Admin for IT and security operations managers. Manage user access, integrations, API keys, and tenant settings.Insider Risk Analyst for HR security and compliance teams. See user behavior anomalies, risky actors, and AI usage patterns, without visibility into threat hunting operations.Organization Admins assign roles in Settings > Users, and changes take effect at that user's next sign-in. We will be expanding additional roles in the future.
See it for yourself If you want to see Detection Versioning on your own rules, set up roles for your team, or dig into anything else that shipped this month, reach out to your account manager or request a demo to see how Nebulock works in your own environment.