Skip to main content
ShadowAI Defense GitHub

Stack picker

Pick your stack

Your selection saves to your browser only. Detection-rule pages will indicate whether each rule is applicable on your stack; runbooks will surface stack-relevant compensating controls.

Coverage matrix

Rules not possible on a given stack with compensating controls noted on the stack page.

Stack # platforms covered Things to know
CrowdStrike + Netskope (Microsoft optional) CS + Netskope CrowdStrike Falcon Insight on the endpoint, Netskope as SWG/CASB at the network layer. A common non-Microsoft-first stack in financial services and enterprise.
Hybrid Multi-Vendor (Microsoft + Netskope + CrowdStrike) Hybrid The most comprehensive stack: Microsoft Sentinel and Purview for SIEM and DLP, Netskope as SWG/CASB, and CrowdStrike Falcon on the endpoint. Common in large enterprises that have best-of-breed tooling across security domains. Provides the deepest detection coverage across all platforms.
Microsoft minimal (E3 only) M365 E3 — limited Microsoft 365 E3 without Defender for Endpoint P2 or Purview add-ons. Detection coverage is limited; relies on network-level signals and policy/comms-driven controls.
Microsoft E3 + Defender for Endpoint P2 + Purview add-ons M365 E3+ add-ons Microsoft 365 E3 with selective add-ons (Defender for Endpoint P2, Purview Information Protection & Governance). Most of the E5 detection power, without Sentinel.
Microsoft E5 (full) M365 E5 Microsoft 365 E5 with Defender for Endpoint P2, Purview Information Protection & Governance, Defender for Cloud Apps, Sentinel, and Conditional Access. The richest in-band coverage.
Netskope SASE NS Netskope Intelligent SSE as the primary SWG/CASB/DLP layer. A Netskope-first stack common in organizations that have standardized on Netskope's Security Service Edge platform for cloud security. Detection relies on Netskope's native AI app discovery and generic network rules.
Okta + Generic SIEM Okta+SIEM Okta as the identity provider with conditional-access policies, paired with a generic SIEM (Splunk, Chronicle, Elastic, or similar) for log analysis. A minimal-tooling stack for organizations without Microsoft E5, CrowdStrike, or Netskope. Relies heavily on network-level signals and identity-based controls.
Zscaler + CrowdStrike ZS+CS Zscaler Internet Access as the SWG/CASB layer, CrowdStrike Falcon on the endpoint. A common stack in large enterprises with a Zscaler-first network security architecture. Relies on generic network rules through the Zscaler proxy and CrowdStrike endpoint telemetry for AI detection.