us-east-1
·
local (no data egress)
·
sha256:7d…a81c
Preview · mock data

Detection rules

23 active · 2 info · FP rate · tune

Active rules

edit severity · escalators · suppression · test
#RuleBase severityFP rate (30d)Fired (30d)
#1Personal account on managed devicecritical
1.2%
47
#2YOLO / Bypass mode enabledcritical
0.0%
12
#3Full-access / disabled sandboxhigh
0.4%
18
#4Base-URL / root-CA override (MITM)critical
3.1%tune?
6
#5Plaintext API keys near agentcritical
5.8%tune?
32
#6Unvetted MCP serverhigh
4.2%
47
#7MCP auto-approve for write toolshigh
2.1%
21
#8Broad Bash auto-allowhigh
1.8%
88
#9Shell-executing hook (LLM-classified)high
7.8%tune?
38
#22IMDS egress reachablecritical
0.0%
8
FP rate tracked via admin "Not risky" + "Override classification" actions. Published quarterly as the noise-floor SLA (target ≤ 2% on hook classification).