UTMStack

Catch real threats in real time, without drowning in alerts

UTMStack runs 600+ detection rules mapped to MITRE ATT&CK on every event as it arrives and raises alerts in real time. Tagging rules, a rule flood guard and the adversary view keep analysts focused on the alerts that matter.

UTMStack · Alerts
The alerts list shows each alert's severity, status, data source, MITRE ATT&CK technique and affected hosts, with counts by status. Opening an alert shows the parties involved, its events and an AI assessment.
  • 600+ rules mapped to MITRE ATT&CK

    Each built-in rule names the attacker tactic and technique it detects, using MITRE ATT&CK, the public catalog of attacker behavior. The rules are open source, so you can read and change them.

  • Real-time alerts

    Rules run on each event before it is stored, so detection does not wait for indexing.

  • Less noise

    Tagging rules mark known false positives automatically. Repeat hits are counted as echoes of one alert instead of piling up as new alerts.

  • Rule flood guard

    If a rule suddenly floods you with alerts, UTMStack switches it off and notifies you, so one bad rule cannot bury the real ones.

  • Threat intelligence on every event

    Each event is also checked against known malicious IP addresses, domains and file hashes.

  • Visual, code and test modes

    Edit a rule in a visual editor, as code or in test mode, and all three stay in sync. Rules can also be exported or disabled.

How a rule decides

Each rule has a condition, an attack category, a MITRE ATT&CK technique and impact scores for confidentiality, integrity and availability. Severity comes from the highest of those three scores. Rules can look back over stored logs, remove duplicate alerts and group new alerts under an existing one. Here are a few of the built-in rules.

  • RDP brute force attack
  • Kerberoasting attack detection
  • AWS CloudTrail log suspended
  • Cobalt Strike DNS beacon pattern detected
  • ESXi ransomware attack detection
UTMStack · Alerting Rules
The alerting rules list: built-in and custom rules with their data types, category, MITRE ATT&CK technique, impact score and an on/off switch. Opening a rule shows its condition as a tree of checks.

See who is attacking what

The adversary view draws a line from each attacker to the alerts they raised and on to the hosts, users or services they hit. One attacker hitting ten servers shows up as one story, not ten separate alerts. The relationship chart helps you decide what to contain first.

UTMStack · Adversary View
The adversary view for the last seven days links each attacking address to the alerts it triggered and the systems it targeted.

Tune out false positives

When an alert turns out to be harmless, create a tagging rule from it with a condition such as a specific host name. Future matching alerts are tagged as false positives automatically, can be hidden from the list, and are skipped by automated response flows.

Triage in one place

Alerts move through automatic review, open, in review and completed. Each alert shows the attacker and target, impact, related raw events and recommended steps. From there you add notes, change the status or turn one or more alerts into an incident.

Questions buyers ask

How many detection rules are included?

More than 600 built-in rules, each mapped to a MITRE ATT&CK technique. They cover Windows, Linux, macOS, cloud platforms, Microsoft 365, firewalls, network sensors and antivirus or endpoint detection tools. New detections are added with every release.

Can I write my own rules?

Yes. Rules use a small, safe expression language with helpers for things like IP ranges, working hours and text matching. Write them in the visual editor, as YAML code or with the AI assistant, and test them in the playground before saving.

How does UTMStack reduce alert fatigue?

Repeat hits are counted as echoes of one alert, tagging rules mark known false positives, and the rule flood guard disables rules that suddenly fire too often. The AI assistant can also review new alerts and close the ones it judges to be false positives, if you allow it.

Do I need a separate threat intelligence feed?

No. Every event is matched against ThreatWinds threat intelligence as part of the platform. You can add other feeds, such as MISP or OpenCTI, with a custom plugin.

Protect your organization this week, not next quarter

Talk to an engineer today, or start using UTMStack in minutes.

Need to extend your SOC team?

Our analysts work as an extension of your security team: they cover nights and weekends, take alert overflow and back you up on hard incidents. Book a 30-minute call to plan the coverage you need.

Want to try UTMStack?

Click through the live demo in your browser with no sign-up, start a free cloud instance, or install the open source edition on your own server in about 30 minutes.