Stairwell Documentation

Guides, playbooks, and reference for deploying Stairwell, investigating with it, and automating it.

Stairwell collects the executables and scripts running across your fleet, keeps them, and lets you ask questions of that history: what is this file, where else is it, what does it resemble, and was it here before anyone told us to look for it. These docs cover all of it, from the first forwarder to the API.

If you are new, read What Is Stairwell, then How Stairwell Works. If you are rolling out forwarders, start at the pre-deployment check. If you are working an alert right now, go to Playbooks and find the situation that matches yours.

Every page assumes you have not used a tool like this before. Where a page needs a concept you may not have met, it links to the page that explains it rather than assuming it.

Where should I start?

Find the row that matches why you are here.

You areStart at
New to StairwellWhat Is Stairwell
Rolling out forwardersPre-Deployment Check
Working an alert right nowAn EDR Alert Just Fired
Wondering what a YARA rule isWhat Is a YARA Rule?
Trying to script somethingswell
Looking for a downloadDownload Center
Connecting another toolIntegrations

Did this page help you?