Open-source detection rules, indexed and cross-referenced.
Sigma, YARA, Suricata, Elastic, Splunk, Falco, Wazuh and more, searchable from one box. One schema across formats, every rule linked back to the file it came from.
Tracked sources
sort
- 01 Azure/Azure-Sentinel 1902
- 02 Bert-JanP/Hunting-Queries-Detection-Rules 449
- 03 chainguard-dev/osquery-defense-kit 270
- 04 chronicle/detection-rules 379
- 05 elastic/detection-rules 1975
- 06 elastic/protections-artifacts 4349
- 07 Emerging Threats Open 50961
- 08 falcosecurity/rules 95
- 09 Neo23x0/signature-base 5904
- 10 panther-labs/panther-analysis 1024
- 11 reversinglabs/reversinglabs-yara-rules 1240
- 12 SigmaHQ/sigma 3783
- 13 socfortress/Wazuh-Rules 2211
- 14 splunk/security_content 2166
- 15 Wazuh Core Ruleset 4420
Newest detections
42637 et-open hidden · include- AzCopy or Azure Storage Explorer Usage on Unusual Host elastic-detection-rules 2026-09-09
- Potential EtherHiding C2 via Curl JSON-RPC Request elastic-detection-rules 2026-09-08
- External Microsoft Teams Sender Domain Risk azure-azure-sentinel 2026-09-07
- File with High Entropy Created by Web Server elastic-detection-rules 2026-09-07
- File with Suspicious Double Extension Created by Web Server elastic-detection-rules 2026-09-07
- Low-Reputation URL Domains Shared in Microsoft Teams azure-azure-sentinel 2026-09-07
- Malicious Email Campaigns by Recipient URL Clicks azure-azure-sentinel 2026-09-07
- Microsoft Teams Call and Message Submissions Over Time azure-azure-sentinel 2026-09-07
- Microsoft Teams Calls and Impersonation-Style Calls by Hour of Day azure-azure-sentinel 2026-09-07
- Microsoft Teams Impersonation Identities by Fake Display Name azure-azure-sentinel 2026-09-07
- Microsoft Teams Senders Triggering URL Safety Tips azure-azure-sentinel 2026-09-07
- Potential Fileless Execution via O_TMPFILE elastic-detection-rules 2026-09-07
- Potential Polyglot Bypass File Created by Web Server elastic-detection-rules 2026-09-07
- Quarantine Malware Reason azure-azure-sentinel 2026-09-07
- Reported Microsoft Teams Calls azure-azure-sentinel 2026-09-07
Most-covered techniques
top 20One technique, every rule mapped to it, grouped by source.
T1190
Exploit Public-Facing Application
6621
T1568
Dynamic Resolution
5931
T1566
Phishing
1862
T1059
Command and Scripting Interpreter
1456
T1071
Application Layer Protocol
1072
T1027
Obfuscated Files or Information
896
T1078
Valid Accounts
734
T1041
Exfiltration Over C2 Channel
717
T1218
System Binary Proxy Execution
632
T1059.001
Command and Scripting Interpreter: PowerShell
522
T1098
Account Manipulation
504
T1562
Impair Defenses
503
T1105
Ingress Tool Transfer
406
T1003
OS Credential Dumping
375
T1548
Abuse Elevation Control Mechanism
361
T1685
Disable or Modify Tools
361
T1055
Process Injection
358
T1021
Remote Services
354
T1059.004
Command and Scripting Interpreter: Unix Shell
350
T1574
Hijack Execution Flow
330