Skip to main content
Panther Knowledge Base

How to write unit tests for stateful Panther detections


What is the recommended approach to writing/maintaining unit tests in rules that are stateful detections?


We recommend using Mocks, as documented here. Mocks can mimic responses from API calls, or other dynamic information used by detection logic, like counting variables.