Adopt detection engineering and keep your security operations flowing
pip install opentide==0.1.0Get startedopentide is the battle-hardened detection engineering standard for teams adopting detection-as-code and scaling their output—with or without agents. Strict validation, a deployment pipeline, modern DevOps workflows, and agent-native constructs powered by an object graph that scales with you.
One DetectionOps pipeline
Draft to deployed. Every stage validated, every platform capability honest. You steer how much is human and how much is agentic.
Validate
Schema, query, and platform honesty checks
Generate
Schemas, templates, and indexes from your repo
Deploy
Seven platforms, dry-run before production
Document
Published narratives for analysts and auditors
From messy, continuous intel to a structured and actionable detection engineering graph
Threats fan into objectives and rules — linked by stable UUIDs across every branch.
From brief to deployable rule — in one loop
Prompt in, objects out: agent skills write the graph, the CLI validates, dry-run deploys.
Built for DetectionOps teams
Specs for authors, CLI for pipelines, MCP for agents. One engine across the surfaces your team already uses.
Platforms
One model. Every stack you actually run.
opentide is built to move with your environment — SIEM today, EDR tomorrow, another vendor when the org consolidates. Same objects, same workflows, adapters that plug in without rewriting your library.
- Cross-platform — author once, target the systems your SOC already trusts
- Flexible — mix Microsoft, Splunk, CrowdStrike, and more in one repo
- Extensible — same adapter contract when you add the next platform
Microsoft Sentinel
Defender for Endpoint
Splunk ES
SentinelOne
Carbon Black
CrowdStrike
HarfangLab
- Yours next
Request a platform
Surfaces
Specs, shell, agents — one DetectionOps engine underneath.
CLI & CI
validate · generate · deploy in the same commands your pipelines already run.
ExploreMCP & agents
Structured tools and skills so agents draft objects humans can still review.
ExploreNormative objects
Threats, objectives, and rules share UUIDs — one contract for authors and agents.
ExploreValidation that sticks
Schema, cross-object refs, and platform query checks when the target supports them.
ExploreThe opentide ecosystem
Engine, specs, library, explorer, and skills — with editor tooling on the way.
- Engine
opentide
DetectionOps engine on PyPI: validate, generate, deploy, document.
- Specs
specifications
Normative object specs, schemas, and vocabularies.
- Registry
library
Public registry of published detection objects.
- App
explorer
Deployable app for exploring OpenTide objects end to end.
- Agents
skills
Canonical agent skills for OpenTide detection engineering.
- Coming soon
language-server
LSP for OpenTide object and query authoring in any editor.
- Coming soon
vscode-extension
VS Code tooling for schemas, validation, and detection workflows.
Set the standard for DetectionOps
Bring your rules, your reviewers, and your agents. opentide structures the flow. You choose how much runs with you — and how much runs on its own.