Open-source detection rules, indexed and cross-referenced.
Sigma, YARA, Suricata, Elastic, Splunk, Falco, Wazuh and more, searchable from one box. One schema across formats, every rule linked back to the file it came from.
Tracked sources
sort
- 01 Azure/Azure-Sentinel 1902
- 02 Bert-JanP/Hunting-Queries-Detection-Rules 450
- 03 chainguard-dev/osquery-defense-kit 270
- 04 chronicle/detection-rules 379
- 05 elastic/detection-rules 2063
- 06 elastic/protections-artifacts 4401
- 07 Emerging Threats Open 51272
- 08 falcosecurity/rules 95
- 09 Neo23x0/signature-base 5904
- 10 panther-labs/panther-analysis 1024
- 11 reversinglabs/reversinglabs-yara-rules 1240
- 12 SigmaHQ/sigma 3783
- 13 socfortress/Wazuh-Rules 2211
- 14 splunk/security_content 2172
- 15 Wazuh Core Ruleset 4420
Newest detections
42744 et-open hidden · include- Bun Runtime Dropped and Executed via Node.js elastic-protections-artifacts 2026-09-30
- Bun Runtime Dropped and Executed via Node.js elastic-protections-artifacts 2026-09-30
- Cursor Hiding Utility via ScreenConnect elastic-protections-artifacts 2026-09-30
- Download of ScreenConnect RMM Installer from Suspicious URL elastic-protections-artifacts 2026-09-30
- ESXi Account Granted Admin Role elastic-detection-rules 2026-09-30
- ESXi Attempt to Force Install a VMware VIB Package elastic-detection-rules 2026-09-30
- ESXi Audit Records Disabled elastic-detection-rules 2026-09-30
- ESXi Curl or Wget Activity elastic-detection-rules 2026-09-30
- ESXi ExecInstalledOnly Protection Disabled elastic-detection-rules 2026-09-30
- ESXi File Made Executable with chmod elastic-detection-rules 2026-09-30
- ESXi Firewall Disabled elastic-detection-rules 2026-09-30
- ESXi Host Logs Deleted with rm elastic-detection-rules 2026-09-30
- ESXi Host Prepared for an Unsigned Install elastic-detection-rules 2026-09-30
- ESXi Local Account Created elastic-detection-rules 2026-09-30
- ESXi Lockdown Mode Disabled elastic-detection-rules 2026-09-30
Most-covered techniques
top 20One technique, every rule mapped to it, grouped by source.
T1190
Exploit Public-Facing Application
6639
T1568
Dynamic Resolution
5963
T1566
Phishing
1865
T1059
Command and Scripting Interpreter
1476
T1071
Application Layer Protocol
1096
T1027
Obfuscated Files or Information
899
T1078
Valid Accounts
740
T1041
Exfiltration Over C2 Channel
731
T1218
System Binary Proxy Execution
636
T1059.001
Command and Scripting Interpreter: PowerShell
527
T1562
Impair Defenses
516
T1098
Account Manipulation
513
T1105
Ingress Tool Transfer
431
T1003
OS Credential Dumping
375
T1548
Abuse Elevation Control Mechanism
362
T1685
Disable or Modify Tools
361
T1055
Process Injection
358
T1021
Remote Services
357
T1059.004
Command and Scripting Interpreter: Unix Shell
357
T1110
Brute Force
331
Most-covered CVEs
top 12Ranked by how many sources cover the CVE, not how many rules mention it.
CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
8
CVE-2024-1709
Authentication bypass using an alternate path or channel
24
CVE-2024-1708
Improper limitation of a pathname to a restricted directory (“path traversal”)
19
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and…
16
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
14
CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
14
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
13
CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
13
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
109
CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
17
CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
17
CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
13