What are EDR detection rules?

NAVIGATION  Policies > Detection Rules

PERMISSIONS   Datto EDR subscription with administrator-level platform access or Datto AV subscription with administrator-level platform access. Service account or administrator-level rights on the target endpoint.

IMPORTANT  Infocyte-created rule bodies can only be copied, modified or viewed by our internal detection engineers. Users can create and edit their own custom rules if desired.

NOTE  Alerts generated by the rules engine display the rule body on the Alert Detail page. For more information, see the article Understanding the Alert Detail page.

This article defines EDR detection rules and explains how to build and edit your own rules using the Detection rules style guide.

Detection rules background

Detection rules run automatically against endpoint audit data as it is received by your instance. These rules help Datto EDR identify potential threats and determine how to address them. The rules we provide analyze your endpoints for processes and behaviors that align with the most common Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) techniques. When a rule is triggered, Datto EDR generates an alert and follows the workflow you have defined in your Automated Response Policy.

You can selectively enable, disable, and customize rules to tailor your instance's threat analysis procedures to the specific needs of your environment. These management options are available on the Detection page.

Detection rules style guide

This style guide is intended for anyone creating custom detection rules, from first-time users to detection engineers.

Detection rules are written using the Infocyte Query Language (IQL). This guide explains how to create detection rules, starting with basic syntax and progressing to techniques used by experienced analysts.

How to Use This Guide

You do not need to read the entire guide. Start with the section that best matches your experience level.

If you are... Start here
New to detection rules Read "What is a detection rule" through "Your first rule," then continue to "Testing a new rule safely." This provides everything needed to begin writing useful detection rules.
Comfortable with queries or scripting, but new to IQL Start with "Step 1: Choose the event type," then work through Steps 1–4 and "Common mistakes."
A detection engineer Use "Field reference," "Matching values," "Common mistakes," and "Notes for detection engineers" as reference material.

All detection rules begin as drafts. Before deploying a rule, validate it against your environment to confirm it behaves as expected. See "Testing a new rule safely" for recommended validation practices.

How to...

FAQ

 

Revision Date
Initial release. 9/8/25
Section: Adding or editing rules - Added Analysis Engine content. 9/17/26
Expanded Detection rules style guide. 9/29/26