ByteRay CQL Hub

Contribute a query

Submit a CQL query or a CSV lookup file directly below, no GitHub account required. We review every submission, test it against live data, and publish it to the hub and the open repository, credited to you as the author.

Direct submit

Markdown is supported: ## headings, **bold**, backtick code, lists, tables. This becomes the explanation section on the query page.

Log sources
Required Falcon modules optional

Submissions are published under the repository's license and credited to you as the author. Contact details stay private and are only used for questions during review.

Thank you — your query is in review. We'll reach out if we have questions, and you'll find it in the hub once it's published, credited to you.
Something went wrong while submitting. Please try again — or open a pull request on GitHub instead.

A lookup file is a CSV you reference from a query with match(), for example a list of Tor exit nodes or known cloud IP ranges. Upload the file, tell us what is in it, and we handle format, naming and publication.

CSV file *
Max file size 10MB.
Uploading...
fileuploaded.jpg
Upload failed. Max size for files is 10 MB.

Preview first rows
Thank you, your lookup file is in review. We check the contents and the format, then publish it on the hub and in the Foundry app lookup sync, credited to you.
Something went wrong while submitting. Please try again, or open a pull request on GitHub instead.