So, you finally stopped whining, clicked on the HEFAISTOS CE GitHub repository, and actually managed to deploy the damn thing. Congratulations, you’ve taken the first step toward not being a complete joke in detection engineering. I didn’t build this platform so you could click around like a trained monkey in some legacy SIEM; it’s here so you can finally do real analysis using ACH (Analysis of Competing Hypotheses) and ditch that dogmatic, universal SIGMA trash for good. We run native platform languages here—KQL, SPL, AQL. Nothing else matters.
Assuming you have admin privileges, just booting it up doesn’t mean you’re done. Here is your strict survival manual on how to kickstart this beast so it’s actually useful.
Phase 1: Armor Up the Engine (Admin Integrations)
Log in and head straight to Admin Integrations. This is your cockpit. Don’t touch anything else until this is locked down.
- Git Repositories: Hook up your repos. We support GitHub, GitLab, and Gitea. If you aren’t pushing your rules and code through git, you don’t exist to me.
- MISP: You need this for CTI integrated tasks. Right now, the AdvOps (Adversary Operations) export to MISP is supported, so wire it up and get your threat intel somewhat organized.
- Platform Credentials: WARNING! This is an experimental feature for pushing your hard-ass rules directly to targeted platforms. We are currently testing integrations for XDR Defender, Sentinel, Splunk, WAZUH, and QRadar. Don’t panic—all creds are encrypted with AES-256 (Fernet), which should keep even the most paranoid psycho sleeping at night.
- SMTP: Yeah, we have a built-in Mailgun integration for the noobs. But if you want to be a pro, set up your own SMTP settings on the Admin Integrations page. Once your custom config is locked in, the built-in Mailgun gets automatically suppressed.
- OpenTide HEF Publish Profiles: Get these templates dialed in. You’ll use them for pushing completed workbenches and rules straight to your git repos and targeted platforms.
- Shared AI: If you’re working with a squad, don’t forget to set up the AI provider for everyone to use. The Maieutic Engine needs its juice to act as your Socratic AI assistant and grill your hypotheses.

Phase 2: Stop Being a Nobody (My Profile)
Got the global settings done? Good. Now switch over to My Profile.
- First things first: Upload your avatar. You are no damn body without an avatar. Nobody on the platform is going to take you seriously if you’re rocking the default ghost icon.
- Sign up for platform messages so they hit your mailbox directly. I don’t want to hear you crying about missing an alert.
- MFA & Passwordless: Typing passwords is for the 90s. Set up MFA right now. For a smooth, passwordless experience, configure a Security Key (or multiple). YubiKey is highly preferred and fully tested.
- AI Assistant Settings: If your admin (which is you, dude) set up “Shared AI,” just enable the Use Shared AI option under AI Assistant Settings. If you’re a lone wolf and want to burn your own API key for popular AI providers, punch it in and select your favorite model. The Socratic assistant won’t function without it.

Phase 3: Map the Battlefield (Coverage Map)
You aren’t doing this for fun. Head over to the Coverage Map and immediately click Update ATT&CK data. This is not optional. You need the adversary playbook up to date. Without fresh data, you can’t effectively track if your TTPs cover basic garbage like T1078 (Valid Accounts) in identity attacks or if you’re entirely blind to T1059 (Command and Scripting Interpreter). Keep the map current.

Phase 4: Time to Hunt (Workbench Hub)
Is everything green? Good. Stop staring at the settings menu and get to the Workbench Hub. Go do some serious detection engineering, apply some proper Capability Abstraction, and catch the bad guys.
