February 5, 2025

Announcing Visual Query Builder and Detection Rule Tags With MITRE Classification

We’ve released two features to improve log search functionality and detection rule organization.

Visual Query Builder – Beta Release

The new query builder interface, currently a beta release, provides a visual alternative to writing raw query syntax. Users can switch between text and visual modes without losing query fidelity.

Capabilities:

  • Dynamic switching between visual and text representations of the same query.
  • Support for all existing query operators and functions.
  • Auto-complete for query fields, values, and functions to streamline building queries.
  • Easy visualization generation: bar charts, line charts, and pie charts.

The visual interface maintains feature parity with text queries while exposing query structure through a composable UI. This allows teams to build complex queries incrementally and share them across skill levels.

Detection Rule Organization with MITRE Tags

Detection rules now support a tagging system with built-in MITRE ATT&CK classification support. Users can also add custom tags to organize rules according to their own schema, which can be helpful as teams’ detection rules lists grow in size from dozens to hundreds.

Detection Rule Tags with MITRE

Tags are propagated in the detection alert messages sent to event sink destinations. Thus, users’ SOAR tools can leverage MITRE tags and custom tags when they receive a Scanner alert and route it to the appropriate response workflow.

Users can also query the _detections index in Scanner using tags as a  facet filter or as an aggregation value, allowing them to compute statistics on which MITRE tactics and techniques are appearing in their alerts the most.

We believe that traditional log architectures are broken for modern log volumes. Scanner enables fast search and detections for log data lakes – directly in your S3 buckets. Reduce the total cost of ownership of logs by 80-90%.
Photo of Cliff Crosland
Cliff Crosland
CEO, Co-founder
Scanner, Inc.
Cliff is the CEO and co-founder of Scanner.dev, which provides fast search and threat detections for log data in S3. Prior to founding Scanner, he was a Principal Engineer at Cisco where he led the backend infrastructure team for the Webex People Graph. He was also the engineering lead for the data platform team at Accompany before its acquisition by Cisco. He has a love-hate relationship with Rust, but it's mostly love these days.