Detection Detail
get_detection_detailRetrieve full details for a detection rule by ID, including query content, MITRE ATT&CK mapping, data sources, false positive guidance, confidence level, and associated threat.
Instructions
Get full details for a specific detection rule by ID — includes query content (SPL/KQL/Sigma), MITRE ATT&CK mapping, data sources, false positive guidance, confidence level, and associated threat.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| detection_id | Yes | Detection ID (e.g. 'det-001' or the detection name) |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| id | No | ||
| name | No |