Open-source detection rules, indexed and cross-referenced.
Sigma, YARA, Suricata, Elastic, Splunk, Falco, Wazuh and more, searchable from one box. One schema across formats, every rule linked back to the file it came from.
Tracked sources
sort
- 01 Azure/Azure-Sentinel 1888
- 02 Bert-JanP/Hunting-Queries-Detection-Rules 449
- 03 chainguard-dev/osquery-defense-kit 270
- 04 chronicle/detection-rules 379
- 05 elastic/detection-rules 1956
- 06 elastic/protections-artifacts 4349
- 07 Emerging Threats Open 50897
- 08 falcosecurity/rules 95
- 09 Neo23x0/signature-base 5905
- 10 panther-labs/panther-analysis 1024
- 11 reversinglabs/reversinglabs-yara-rules 1240
- 12 SigmaHQ/sigma 3783
- 13 socfortress/Wazuh-Rules 2211
- 14 splunk/security_content 2157
- 15 Wazuh Core Ruleset 4420
Newest detections
42617 et-open hidden · include- Display Name - Detect Teams IT Helpdesk Impersonation Msg Phishing & Vishing azure-azure-sentinel 2026-09-04
- Potential Entra ID PRT Extraction via BrowserCore elastic-detection-rules 2026-09-04
- Linux Crontab Enumeration splunk-security-content 2026-09-03
- Quarantine Release Percentage azure-azure-sentinel 2026-09-03
- Top accounts performing user submissions (FP) azure-azure-sentinel 2026-09-03
- User Email Submissions (FP) - Top Inbound P2 Senders azure-azure-sentinel 2026-09-03
- User Email Submissions (FP) - Top Inbound Subjects azure-azure-sentinel 2026-09-03
- User Email Submissions (FP) - Top Intra-Org P2 Senders azure-azure-sentinel 2026-09-03
- User Email Submissions (FP) - Top P2 Sender Domains azure-azure-sentinel 2026-09-03
- User Email Submission Trend (FP) azure-azure-sentinel 2026-09-03
- User Submissions by Detection Method - Phish (FP) azure-azure-sentinel 2026-09-03
- User Submissions by Detection Method - Spam (FP) azure-azure-sentinel 2026-09-03
- User Submissions by Submission State (FP) azure-azure-sentinel 2026-09-03
- Automated Investigation Outcomes by Day azure-azure-sentinel 2026-09-02
- Automated Remediation Delivery to Action Latency azure-azure-sentinel 2026-09-02
Most-covered techniques
top 20One technique, every rule mapped to it, grouped by source.
T1190
Exploit Public-Facing Application
6613
T1568
Dynamic Resolution
5929
T1566
Phishing
1848
T1059
Command and Scripting Interpreter
1448
T1071
Application Layer Protocol
1071
T1027
Obfuscated Files or Information
896
T1078
Valid Accounts
730
T1041
Exfiltration Over C2 Channel
716
T1218
System Binary Proxy Execution
632
T1059.001
Command and Scripting Interpreter: PowerShell
521
T1562
Impair Defenses
502
T1098
Account Manipulation
501
T1105
Ingress Tool Transfer
406
T1003
OS Credential Dumping
375
T1548
Abuse Elevation Control Mechanism
361
T1685
Disable or Modify Tools
361
T1055
Process Injection
358
T1021
Remote Services
354
T1059.004
Command and Scripting Interpreter: Unix Shell
349
T1574
Hijack Execution Flow
328