Stairwell Documentation
Guides, playbooks, and reference for deploying Stairwell, investigating with it, and automating it.
Stairwell collects the executables and scripts running across your fleet, keeps them, and lets you ask questions of that history: what is this file, where else is it, what does it resemble, and was it here before anyone told us to look for it. These docs cover all of it, from the first forwarder to the API.
If you are new, read What Is Stairwell, then How Stairwell Works. If you are rolling out forwarders, start at the pre-deployment check. If you are working an alert right now, go to Playbooks and find the situation that matches yours.
Every page assumes you have not used a tool like this before. Where a page needs a concept you may not have met, it links to the page that explains it rather than assuming it.
Where should I start?
Find the row that matches why you are here.
| You are | Start at |
|---|---|
| New to Stairwell | What Is Stairwell |
| Rolling out forwarders | Pre-Deployment Check |
| Working an alert right now | An EDR Alert Just Fired |
| Wondering what a YARA rule is | What Is a YARA Rule? |
| Trying to script something | swell |
| Looking for a download | Download Center |
| Connecting another tool | Integrations |
Updated 4 days ago