Nightfall Detection Rules: How to Use Regex Context Rules

Last updated: January 29, 2026

Purpose

To set up and use RegEx context rules within Nightfall

Environment

  • Nightfall Web Console: Detection

    • Detectors

Resolution

To create effective regex patterns in Nightfall:

  1. Use RE2-compatible syntax for your patterns

  2. Test your regex using a regex testing tool that supports RE2

  3. Refer to the RE2 documentation for supported syntax

Example

To create exclusion patterns, consider reframing the RegEx logic, instead of using negative "lookaheads".

For example, use a combination of supported RE2 features to achieve the same result, as opposed to using a negative lookahead pattern like, `Authorization(?!(?:.*Basic))`,

NOTE: Nightfall RegEx rules uses RE2. RE2 does not support:

  • Lookbehind assertions

  • Some advanced lookahead patterns, like `(?!)`

  • Backreferences

Remember to always test your regex patterns before implementing them in production to ensure they match your intended patterns correctly.