The problem
Your detection library is a form of vendor lock-in.
Rules written against Splunk field names don't run on Sentinel. Switch tools and years of detection engineering evaporates overnight. The content you built is a genuine asset, but today it's trapped.
Without Derwent Labs
Detections coupled to one SIEM's proprietary schema
Shared community content you can't actually run
Migrations that mean rewriting every rule by hand
What you get
With Derwent Labs in front of your stack
One schema, every backend
Detections target OCSF, not a vendor dialect, so the same logic runs on Splunk, Sentinel, Chronicle, or whatever comes next.
Adopt shared content instantly
Drop in a detection pack another team spent years refining and have it firing in five minutes.
Future-proof your library
Your detection engineering becomes a portable asset that outlives any single tooling decision.