Stack picker
Pick your stack
Your selection saves to your browser only. Detection-rule pages will indicate whether each rule is applicable on your stack; runbooks will surface stack-relevant compensating controls.
Coverage matrix
Rules not possible on a given stack with compensating controls noted on the stack page.
| Stack | # platforms covered | Things to know |
|---|---|---|
| CrowdStrike + Netskope (Microsoft optional) | CS + Netskope | CrowdStrike Falcon Insight on the endpoint, Netskope as SWG/CASB at the network layer. A common non-Microsoft-first stack in financial services and enterprise. |
| Hybrid Multi-Vendor (Microsoft + Netskope + CrowdStrike) | Hybrid | The most comprehensive stack: Microsoft Sentinel and Purview for SIEM and DLP, Netskope as SWG/CASB, and CrowdStrike Falcon on the endpoint. Common in large enterprises that have best-of-breed tooling across security domains. Provides the deepest detection coverage across all platforms. |
| Microsoft minimal (E3 only) | M365 E3 — limited | Microsoft 365 E3 without Defender for Endpoint P2 or Purview add-ons. Detection coverage is limited; relies on network-level signals and policy/comms-driven controls. |
| Microsoft E3 + Defender for Endpoint P2 + Purview add-ons | M365 E3+ add-ons | Microsoft 365 E3 with selective add-ons (Defender for Endpoint P2, Purview Information Protection & Governance). Most of the E5 detection power, without Sentinel. |
| Microsoft E5 (full) | M365 E5 | Microsoft 365 E5 with Defender for Endpoint P2, Purview Information Protection & Governance, Defender for Cloud Apps, Sentinel, and Conditional Access. The richest in-band coverage. |
| Netskope SASE | NS | Netskope Intelligent SSE as the primary SWG/CASB/DLP layer. A Netskope-first stack common in organizations that have standardized on Netskope's Security Service Edge platform for cloud security. Detection relies on Netskope's native AI app discovery and generic network rules. |
| Okta + Generic SIEM | Okta+SIEM | Okta as the identity provider with conditional-access policies, paired with a generic SIEM (Splunk, Chronicle, Elastic, or similar) for log analysis. A minimal-tooling stack for organizations without Microsoft E5, CrowdStrike, or Netskope. Relies heavily on network-level signals and identity-based controls. |
| Zscaler + CrowdStrike | ZS+CS | Zscaler Internet Access as the SWG/CASB layer, CrowdStrike Falcon on the endpoint. A common stack in large enterprises with a Zscaler-first network security architecture. Relies on generic network rules through the Zscaler proxy and CrowdStrike endpoint telemetry for AI detection. |