This is the environment used to test rules, generate logs, and validate playbooks. If a detection can’t survive messy reality, it doesn’t belong in a repo.
Drop images into assets/screenshots/ and link them on this page.
Placeholders are included so you don’t forget.
assets/screenshots/detection_firing.pngassets/screenshots/splunk_pivot.png