We’ve all been there. You have three 32-inch monitors, and somehow, it’s still not enough screen real estate. Between fifty browser tabs, your Microsoft Sentinel workspaces, and a terminal window you forgot why you opened, cognitive overload is real. When you’re deep in the trenches hunting down T1059.001 (PowerShell) execution or mapping out defensive coverage against T1078 (Valid Accounts), the absolute last thing you need is a bloated UI screaming for your attention with features you aren’t currently using.
That is exactly why we built Workbench Visibility. It is not about some convoluted management reporting structure; it’s about preserving your sanity and your screen space.
Sometimes, you’re architecting a massive, multi-staged detection for an APT campaign and need every tool at your disposal. Other times? You just need to slap a single, surgical IP address indicator into a quick rule. If you are just doing a rapid drive-by detection, why on earth would you want the Capability Abstraction Map eating up half your screen?

The Cockpit Controls
Take a look at the Detection Strategy & Context panel. We’ve handed you the power to toggle exactly what you want to look at, putting you in control of the signal-to-noise ratio in your own workspace.
It starts with the core macro choices: Simple Mode versus Advanced Mode. Simple mode strips the workbench back to the absolute bare metal for when you just need to get in, write KQL, and get out. Advanced mode gives you the keys to the entire armory.
For those who like to build their own custom cockpits, we wired in granular checkboxes. If your current sprint doesn’t require playing with the SOAR pipeline, simply uncheck Part 4: SOAR Configuration. Already know your testing parameters and don’t need the UI hand-holding? Kill Part 5: Testing & Validation. Don’t need the Capability Abstraction Map or the Capability Abstraction Library today? Turn them to dust. Hide the Activity Overview while you’re at it.
Reclaim your pixels. Reclaim your focus.
The Non-Negotiables
But don’t get too trigger-happy with the checkboxes. We gave you flexibility, not permission to be lazy. If you look at the bottom of the configuration panel, you’ll notice the greyed-out items:
- Part 1: Detection Strategy: Required section
- Part 2: Deep Dive: Required section
- Part 3: Detection Rule: Required section
- Part 6: Review Workflow: Required section
You cannot hide the actual work. You still have to define your strategy, document the deep dive, write the actual logic, and put it through a review workflow. We are building a high-fidelity detection engineering platform here, not a script-kiddie notepad.
Lock It In
Finally, because we know detection engineers despise repeating themselves, we added the most important feature on the page: the “Save current layout as my default” button. Once you’ve tuned the UI to your exact, pedantic specifications, just hit that button. The next time you fire up the HEFAISTOS workbench to draft a Level 4: Strong (Tool) analytic, the system will remember exactly how streamlined you like your interface to be.
We built HEFAISTOS to adapt to the hunt. Keep your workspace clean, your queries sharp, and let the workbench bend to your will.