Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
deadair — Finds the detection rules in your SIEM that are running blind | Kitploit
Tools/GitHubGitHub/big-comfy/deadair
Vulnerability AnalysisConfiguration AuditingLog Analysis
GitHubbig-comfy/deadair

deadair

Finds the detection rules in your SIEM that are running blind

View Repository
618524 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

deadair - SIEM detection coverage health

CI Release Go 1.26 License: Apache-2.0

deadair checks whether enabled SIEM detections still have the telemetry they need.
It reports missing or stale data, ingest delays, and schema mismatches.

Runs locally · Read-only · No agent · No telemetry upload

Read the technical write-up · Featured in Detection Engineering Weekly · Featured in tl;dr sec #341

An Elastic scan showing missing and stale inputs, missing fields, and delayed events

Missing fields and delayed events in a disposable Elastic lab. Open the image for the short recording with playback controls, or reproduce it with make record-scan-lab.

Why deadair

A rule can be enabled, scheduled, and error-free after the data it needs has disappeared. deadair reads the live rule inventory, resolves each rule's inputs using the backend's native semantics, and checks the concrete sources behind them.

It catches:

  • rules whose index, alias, or data-stream selectors resolve to nothing;
  • mixed-selector rules where one declared input has disappeared while another still resolves;
  • rules whose matching sources are all stale or empty;
  • on Elastic, rules running with missing declared fields;
  • on Elastic and eligible Sentinel Scheduled rules, an ingest-lag blind window;
  • on Sentinel, rules whose known sources use an incompatible Basic or Auxiliary table plan;
  • on Elastic and OpenSearch, healthy telemetry that no enabled detection reads.

deadair supports Elastic Security, OpenSearch Security Analytics, and Microsoft Sentinel.

Quick start

Download a binary for macOS, Linux, or Windows from GitHub Releases, or install with Go:

go install github.com/alephnull-sh/deadair/cmd/deadair@latest

Print the read-only setup for your SIEM:

deadair setup elastic      # Elastic Security
deadair setup opensearch   # OpenSearch Security Analytics
deadair setup sentinel     # Microsoft Sentinel

Run one setup, then verify and scan:

deadair check   # verify the credential can scan
deadair scan    # assess live rules and telemetry

Exit codes are stable: 0 passes the configured gate, 1 means gated findings, and 2 means the scan failed.

To investigate a source and its consuming detections:

deadair scan --json-out report.json --html-out report.html
deadair inspect --source CommonSecurityLog report.json

Use a source name from your report. The investigation guide also covers individual Sentinel feeds, maintenance, and recovery tracking.

How it works

StageWhat deadair does
Inventoryreads enabled detections and the inputs they declare
Resolveuses native index resolution on Elastic and OpenSearch; on Sentinel, combines KQL analysis with table, watchlist, saved-function, ASIM, and mapped cross-workspace evidence
Measurechecks source freshness and timing, plus schema and storage where the backend supports them
Reportemits terminal, JSON, HTML, fleet rollups, and Prometheus metrics with the evidence behind each verdict

Sentinel follows the same rule-to-source model and adds literal watchlists, saved functions, ASIM parsers, mapped workspaces, and summary-table lineage. It also shows when a filtered slice of a shared table has gone quiet or a summary pipeline has fallen behind.

The usage guide describes the evidence rules, and the validation record records the live test coverage.

A quiet London firewall feed and its dependent detection inside Sentinel CommonSecurityLog

Two firewall feeds share CommonSecurityLog. One stops; the other keeps reporting. The recording shows the saved failure and recovery scans. See the validation record for the lab conditions.

deadair checks whether a detection's telemetry is present and healthy. It does not validate rule logic or prove that a simulated attack will fire an alert. Use static rule validation and end-to-end detection tests for those jobs.

Findings

FindingMeaningFirst check
no matching sourcenone of the rule's inputs resolve to a visible index, data stream, or Sentinel tablepattern changes, missing integrations, and credential scope
all sources stale or emptyevery resolved source is unusable right nowsource cadence and the ingest path
missing fieldsan Elastic rule-declared field is absent or non-searchable in one or more resolved sources after every source mapping was readparser, package, and mapping changes
lag blind windowpaired-event p95 ingest lag exceeds the rule's lookback marginrule interval, lookback, timestamp override, and pipeline delay
partial input coveragethe complete expression resolves, but one positive selector within it resolves emptymigrations, fallback selectors, and expected alternatives; informational unless policy gates it
source plan incompatiblea Sentinel rule depends on a Basic or Auxiliary table that is not eligible for the analytics-rule evidence pathtable plan and rule type
source degradationa source is stale, empty, low-volume, or schema-driftedsource history and expected maintenance
unused telemetryon Elastic or OpenSearch, data is being stored but no enabled local detection resolves to itdisabled rules and intentional collection
expected producer quieta configured Sentinel vendor, product, or device feed hasn't reported within its thresholdthat feed's sender and collector
summary pipeline unhealthya relevant Sentinel summary job failed or its last success is overduethe native execution record and summary query

Producer and summary-pipeline findings affect exit status when their classes are selected in the policy. A quiet device feed is reported separately from other consumers of its shared table.

Download Tool