Adopt detection engineering and keep your security operations flowing

pip install opentide==0.1.0Get started

opentide is the battle-hardened detection engineering standard for teams adopting detection-as-code and scaling their output—with or without agents. Strict validation, a deployment pipeline, modern DevOps workflows, and agent-native constructs powered by an object graph that scales with you.

One DetectionOps pipeline

Draft to deployed. Every stage validated, every platform capability honest. You steer how much is human and how much is agentic.

  1. Validate

    Schema, query, and platform honesty checks

  2. Generate

    Schemas, templates, and indexes from your repo

  3. Deploy

    Seven platforms, dry-run before production

  4. Document

    Published narratives for analysts and auditors

From messy, continuous intel to a structured and actionable detection engineering graph

Threats fan into objectives and rules — linked by stable UUIDs across every branch.

From brief to deployable rule — in one loop

Prompt in, objects out: agent skills write the graph, the CLI validates, dry-run deploys.

Built for DetectionOps teams

Specs for authors, CLI for pipelines, MCP for agents. One engine across the surfaces your team already uses.

Platforms

One model. Every stack you actually run.

opentide is built to move with your environment — SIEM today, EDR tomorrow, another vendor when the org consolidates. Same objects, same workflows, adapters that plug in without rewriting your library.

  • Cross-platform — author once, target the systems your SOC already trusts
  • Flexible — mix Microsoft, Splunk, CrowdStrike, and more in one repo
  • Extensible — same adapter contract when you add the next platform

The opentide ecosystem

Engine, specs, library, explorer, and skills — with editor tooling on the way.

Set the standard for DetectionOps

Bring your rules, your reviewers, and your agents. opentide structures the flow. You choose how much runs with you — and how much runs on its own.