Your Next-Gen SIEM, engineered by the team behind the CQL Hub.

We maintain the CQL Hub, an open library of 174 queries anyone can copy. SIEM Engineering is the work that comes after: onboarding the log sources those queries need, adapting the logic to your environment, setting thresholds and keeping false positives down. Delivered by CrowdStrike Certified SIEM Engineers from Munich.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
This is some text inside of a div block.
CCSE-certified
CrowdStrike Certified SIEM Engineers on every engagement
350+ use cases
A tested catalogue, adapted to your log sources
174 queries
Public on the CQL Hub, free to use, with or without us
Yours to keep
Every rule documented and handed over at the end
The work

Everything between a raw log line and an alert somebody acts on.

CrowdStrike Falcon Next-Gen SIEM gives you the platform. What it does not give you is the detection content for your environment: your log sources, your applications, your definition of normal. That layer is built, and it is where most SIEM projects either succeed or quietly stall.

Data
Where a detection gets its evidence
Log sources onboarded through the Falcon connector packs
Custom parsers for systems that have no connector
Field mapping into the CrowdStrike data model
Detection
What turns events into an alert
Correlation rules from our catalogue of 350+ use cases
Custom rules for your own applications
Thresholds and exclusions tuned on your own traffic
Operation
What keeps it working after go-live
Dashboards and reporting for reviews and audits
Fusion SOAR playbooks for the repetitive response steps
Regular review as the environment changes

All three layers run inside the Falcon platform you already license. No second system, no separate log store, and no data leaving the EU.

The bridge

From a copied query to a detection your team trusts.

The CQL Hub is public and free: 174 CQL queries and 15 lookup files for Falcon Next-Gen SIEM and LogScale, plus a CrowdStrike-certified Foundry app that keeps the lookups current in your tenant. Many teams take it from there on their own. Three things regularly stop the ones who cannot.

A query only works if the log source behind it does
Every query assumes a data source and a field naming. If that source is not onboarded, or its fields land elsewhere in your data model, the query returns nothing and looks broken. Getting the data in, parsed and mapped is usually the larger half of the job.
A detection that fires all day gets switched off
A query becomes a correlation rule once it has a schedule, a threshold, exclusions for the systems that legitimately behave that way, and a documented response. Skip that step and the rule produces noise, and noise gets muted within a fortnight.
Rules drift away from the template they came from
A rule created from a CrowdStrike template is a one-time copy and stays disconnected from it. When the template improves later, your rule never hears about it. Our Drift Checker shows line by line what has diverged, and in the environments we operate we keep the catalogue current for you.
Foundry › App catalog
ByteRay CQL Hub
Authored by ByteRay GmbH
◉ Certified app
Use case: Threat intelligence
Vendor: ByteRay
Requires: Falcon Next-Gen SIEM
The same team that maintains the public query library builds and tunes detections in client environments. The app is reviewed by CrowdStrike and released to all customers, not self-published.

The library itself stays open and free: browse all 174 queries on the CQL Hub, no account and no contract required.

Two starting points

Most engagements begin in one of two places.

Some teams already run Falcon Next-Gen SIEM and want more out of it. Others are still on a legacy platform and need to move without losing detection coverage on the way. The route differs, the deliverable does not: rules that fire on the right things, documented well enough for your team to own them.

You already run Next-Gen SIEM.

Starting point
Log sources are connected, a handful of rules are active, and in practice the platform is used for searching after the fact. The detections that exist were built once at go-live and never revisited. Nobody can say which parts of the attack surface are actually covered.
What we do
A health check first: platform configuration, data quality per log source, and detection coverage mapped against MITRE ATT&CK so the gaps are visible before anything is added. Then use cases from our catalogue, adapted to your log sources, tested and tuned until the alert volume is one your analysts will actually work.
What you end up with
A documented rule set with known coverage, and a prioritised list of the gaps still open, each with an owner and a date.

You are moving off a legacy SIEM.

Starting point
Years of rules, parsers and reports sit in the old platform, the licence has an end date, and nobody wants a detection gap during the changeover. The team has to stay able to work throughout.
What we do
An inventory of the existing environment: log sources, data models, active use cases. From that a staged migration plan with dependencies, dates and responsibilities. The new environment is built alongside the old one, use cases are carried over and re-tested, and we stay on the project through go-live.
What you end up with
The old platform is switched off after the last use case has proven itself in the new one, not before.
The hard part

What decides whether a rule survives its first month.

Copying a query out of the hub and running it once is easy. Keeping a detection accurate while your environment keeps moving is a different discipline. In our projects it comes down to five questions.

01
Is the data there, in the shape the rule expects?
A rule returns nothing when a field is named differently or a log source stopped delivering three weeks ago. Nothing fails loudly. The rule simply never fires again, and that usually surfaces during an incident review rather than before one.
02
What counts as normal in your environment?
The same behaviour is an attack in one network and a nightly batch job in another. Thresholds and exclusions can only be set against your own traffic, which is why we tune on real data over a defined observation period instead of shipping defaults.
03
What happens to the alert after it fires?
A detection without a documented response produces work, not safety. Every rule we hand over states what triggered it, what to check first and what to do next, so it can be worked at three in the morning by somebody who did not build it.
04
What does this rule cost to run every day?
Search scope and scheduling frequency drive compute. A rule written against a small test set can get expensive at production volume, and expensive rules are the ones that get disabled for budget reasons rather than security ones.
05
Who maintains this a year from now?
Your environment changes, CrowdStrike improves its templates, and rules drift away from both. Documentation and a handover session for your team are part of the project, not of a follow-up quote. Where we operate the platform, the review is part of the service.
Health check first
We measure coverage and data quality before adding anything
350+ use cases
A tested catalogue, adapted to your log sources and applications
Documented, handed over
Your team can run and extend the rules on its own afterwards
Scope check

How much of this you actually need from us.

Level 1
Copy from the CQL Hub
Take a query, paste it into your console, run it. Public, free, no account and no contract.
Doable without us
Level 2
Install the Foundry app
The certified ByteRay CQL Hub app syncs the lookup files into your tenant daily and checks your correlation rules for drift and duplicates.
Doable without us
Level 3
Detections built for your environment
Log sources onboarded and parsed, rules adapted from our catalogue, thresholds tuned on your traffic, response documented per rule.
Project work
Level 4
The platform run for you
Implementation or migration first, then day-to-day operation of the platform and its detections, with our analysts on the alerts if you want that too.
Managed service

Most teams sit at level 3. If the real gap is that nobody is watching the alerts around the clock, our Managed CSIRT and MDR service covers that side.

Common questions

What usually gets clarified before the first call.

Do we have to work with you to use the CQL Hub?

No. The library is public and free, with or without a contract, and it stays that way. It exists because working CQL queries for Falcon Next-Gen SIEM are hard to find anywhere else. If the queries are all you need, take them.

We already have a SIEM. Can you migrate it?

Yes, and it is one of the two ways most projects start. We inventory the log sources, data models and active use cases in the existing platform, build a staged migration plan with dependencies and dates, stand up the new environment alongside the old one and carry the use cases over with testing at each stage.

How long does a SIEM project take?

An implementation with a defined set of log sources and use cases runs a few weeks. A migration depends on how many rules and parsers sit in the old platform, which is exactly what the inventory in the first phase establishes. Larger projects are staged so detections reach production early instead of everything landing at the end.

Do you work in English?

Yes. Rule documentation, runbooks and reporting are delivered in English or German. The team sits in Munich, so log data and evidence stay inside the EU. ByteRay is listed by Germany's federal cyber agency (BSI) as a qualified APT response provider under Section 3 BSIG.

Do you also run the SIEM afterwards?

Yes. Either the platform alone, which covers operation, log source monitoring, parsing and normalisation checks, updates and regular reporting, or the platform together with round-the-clock monitoring of its alerts through our Managed CSIRT. Both work alongside Falcon Complete.

How do we know you can actually do this?

The fastest check is your own Falcon console: under Foundry › App catalog you will find the ByteRay CQL Hub marked as a certified app, reviewed by CrowdStrike and released to all customers rather than self-published. The public library behind it is at cql-hub.com, and our consultants hold the CrowdStrike Certified SIEM Engineer qualification.

z
z
z
z
i
i
z
z
Let's scope your
SIEM project.
A 30-minute call with a CrowdStrike-certified SIEM engineer. Bring the log sources you have and the detections you are missing, and you will get an honest read on what is worth doing first.
Prefer to book a slot right away?
Book an intro call