{"repo":"alephnull-sh/deadair","free":true,"listed":false,"github":"https://github.com/alephnull-sh/deadair","clone":"git clone https://github.com/alephnull-sh/deadair.git","description":"Finds the detection rules in your SIEM that are running blind","language":"Go","stars":16,"topics":["cli","detection-engineering","elasticsearch","golang","opensearch","security-monitoring","siem"],"license":"Apache-2.0","category":"cli-tools","readme_excerpt":"Open-source SIEM detection health. Find enabled detections that are blind because their telemetry is missing, stale, late, or schema-incompatible. Runs locally · Read-only · No agent · No telemetry upload Read the technical write-up · Featured in Detection Engineering Weekly · Featured in tl;dr sec #341 Real scan of a disposable Elastic lab with deliberately missing, stale, late, and unused telemetry. Reproduce it with make record-scan-lab . Why deadair A rule can be enabled, scheduled, and error-free while the data it needs is gone. deadair reads the live rule inventory, resolves each rule's inputs using the backend's native semantics, and checks the concrete sources behind them. It catches: - rules whose index, alias, or data-stream selectors resolve to nothing; - rules whose matching sources are all stale or empty; - rules running with missing fields or an ingest-lag blind window; - healthy telemetry that no enabled detection reads. deadair currently works with Elastic Security and OpenSearch Security Analytics. Quick start Download a binary for macOS, Linux, or Windows from GitHub Releases, or install with Go: Connect a read-only SIEM credential: Exit codes are stable: 0 is healthy, 1 means findings, and 2 means the scan failed. How it works Stage What deadair does --- --- Inventory reads enabled detections and the inputs they declare Resolve asks Elastic or OpenSearch to resolve index patterns, aliases, data streams, selectors, and remote inputs Measure checks document c","default_branch":null,"files":null,"tree":[],"storefront":"/r/alephnull-sh","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/alephnull-sh/deadair/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}