Skip to main content
The Content Management System (CMS) is a workspace’s Detection Rules page. It lists the detection rules running in that workspace’s Microsoft Sentinel and Microsoft Defender XDR, and lets you add, enable, disable, and delete them without leaving ContraForce.
Who is this for? Workspace Owners, Content Admins, and security engineers who manage the detection rules for a single customer workspace.
The CMS and the Content Management Center are different features. The CMS works inside one workspace, on the rules running there. The Content Management Center is the top-level, cross-workspace library that versions detection content in repositories and deploys it to the workspaces you choose.

Opening the CMS

Open a workspace’s CMS in any of these ways:
  • In Workspaces, select the flask icon on the workspace’s card.
  • In Workspaces → [workspace] → Modules, select the flask icon on the Microsoft Sentinel or Microsoft Defender XDR module.
  • Press Ctrl + K to open Quick Actions and choose Go to [workspace] analytics.
The page opens as Workspaces → [workspace] → Detection Rules.

Detection Rules Tabs

Each tab shows how many rules it holds, and the Severity, Name, Last modified date, and Status of each rule.
Workspaces with the Sumo Logic Detection Module connected also have a Sumo Logic Monitors tab on this page, listing the Sumo Logic organization’s monitors.

Finding Rules

  • Search by rule name.
  • Filter by Severity (High, Medium, Low, Info, plus Other for analytics rules) and Status (Enabled or Disabled).
  • Select the refresh icon to reload the list.
  • Select the view icon on a row to see the rule’s details.

Adding a Rule

Select Add rule on the Sentinel Analytical Rules tab, or Add detection on the Defender Custom Detections tab.

Enabling, Disabling, and Deleting Rules in Bulk

1

Select the Rules

Select the checkbox on each rule, or Select all to select every rule that matches the current filters.
2

Open Actions

Select Actions (N), where N is the number of rules selected.
3

Choose the Action

Choose Enable selected, Disable selected, or Delete selected.
Delete selected removes the rules from the workspace, not just from this list. Check your selection first, especially after using Select all.

CMS or Content Management Center?

The Content Management Center manages the same two rule types as the CMS: Microsoft Sentinel analytics rules and Microsoft Defender XDR custom detections. See Sentinel and Defender in the Content Management Center.

Content Management Center

Version and deploy detection content across workspaces

Microsoft Sentinel Module

Connect Sentinel to a workspace

Workspace Center

Manage workspace settings and modules

Roles & Permissions Reference

Which roles can manage detection rules

Questions about the Content Management System? Contact us at support@contraforce.com.
Last modified on October 8, 2026