Detection Packs
Detection packs provide pre-built detection content published and maintained by Anomali, enabling you to quickly deploy detection rules and saved searches without creating your own AQL queries. Each pack focuses on a specific detection theme, such as user and entity behavior or network anomalies, and is mapped to relevant MITRE ATT&CK techniques.
When you install a Detection Pack, its rules are added in a disabled state. The underlying detection logic is read-only, allowing Anomali to centrally deliver updates without modifying your operational configuration. You can customize operational settings such as the risk score, lookback window, and run schedule, while the detection logic itself remains protected. If you need to modify the detection logic, duplicate the rule to create a fully editable custom copy. See Duplicating Detection Rules for details,
To access available Detection Packs, navigate to ThreatStream Next Gen > Security Operations > Detection Rules and click Detection Packs.