Open-source detection rules, indexed and cross-referenced.
Sigma, YARA, Suricata, Elastic, Splunk, Falco, Wazuh and more, searchable from one box. One schema across formats, every rule linked back to the file it came from.
Tracked sources
sort
- 01 Azure/Azure-Sentinel 1902
- 02 Bert-JanP/Hunting-Queries-Detection-Rules 450
- 03 chainguard-dev/osquery-defense-kit 270
- 04 chronicle/detection-rules 379
- 05 elastic/detection-rules 2032
- 06 elastic/protections-artifacts 4353
- 07 Emerging Threats Open 51227
- 08 falcosecurity/rules 95
- 09 Neo23x0/signature-base 5904
- 10 panther-labs/panther-analysis 1024
- 11 reversinglabs/reversinglabs-yara-rules 1240
- 12 SigmaHQ/sigma 3783
- 13 socfortress/Wazuh-Rules 2211
- 14 splunk/security_content 2170
- 15 Wazuh Core Ruleset 4420
Newest detections
42708 et-open hidden · include- Potential FileFix Command via Windows Explorer Address Bar elastic-detection-rules 2026-09-28
- Potential NetScaler Log Poisoning Command Injection Attempt elastic-detection-rules 2026-09-28
- Potential TerminalFix Cloudflare Lure in PowerShell elastic-detection-rules 2026-09-28
- Potential ClickFix Command via Windows Run Dialog elastic-detection-rules 2026-09-24
- Curl Download Activity from npm Package Install elastic-detection-rules 2026-09-23
- Launch Item Registration with Suspicious Executable Path via macOS Security Events elastic-detection-rules 2026-09-22
- Persistence via a Hidden Plist Filename via macOS Security Events elastic-detection-rules 2026-09-22
- Suspicious PowerShell from npm Package Install elastic-detection-rules 2026-09-22
- Cisco NVM - Osascript Network Connection for a Long Duration splunk-security-content 2026-09-18
- MacOS Osascript Executing Interactive Shell splunk-security-content 2026-09-18
- MacOS Osascript Executing JavaScript Code With ObjC splunk-security-content 2026-09-18
- Potential Tunneling via AWS IoT Secure Tunneling Localproxy elastic-detection-rules 2026-09-18
- Excessive Sudo Authentication Failures via macOS Security Events elastic-detection-rules 2026-09-17
- Privilege Escalation via Parallels Appliance Extract Argument Injection elastic-detection-rules 2026-09-17
- Anthropic Activity from a Suspicious User Agent elastic-detection-rules 2026-09-16
Most-covered techniques
top 20One technique, every rule mapped to it, grouped by source.
T1190
Exploit Public-Facing Application
6632
T1568
Dynamic Resolution
5941
T1566
Phishing
1865
T1059
Command and Scripting Interpreter
1470
T1071
Application Layer Protocol
1095
T1027
Obfuscated Files or Information
898
T1078
Valid Accounts
737
T1041
Exfiltration Over C2 Channel
731
T1218
System Binary Proxy Execution
636
T1059.001
Command and Scripting Interpreter: PowerShell
526
T1098
Account Manipulation
511
T1562
Impair Defenses
510
T1105
Ingress Tool Transfer
421
T1003
OS Credential Dumping
375
T1548
Abuse Elevation Control Mechanism
362
T1685
Disable or Modify Tools
361
T1055
Process Injection
358
T1021
Remote Services
354
T1059.004
Command and Scripting Interpreter: Unix Shell
353
T1110
Brute Force
330
Most-covered CVEs
top 12Ranked by how many sources cover the CVE, not how many rules mention it.
CVE-2025-59287
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
8
CVE-2024-1709
Authentication bypass using an alternate path or channel
24
CVE-2024-1708
Improper limitation of a pathname to a restricted directory (“path traversal”)
19
CVE-2025-55182
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and…
16
CVE-2022-22965
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
14
CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
14
CVE-2024-3400
PAN-OS: Arbitrary File Creation Leads to OS Command Injection Vulnerability in GlobalProtect
13
CVE-2025-53770
Microsoft SharePoint Server Remote Code Execution Vulnerability
13
CVE-2021-44228
Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints
109
CVE-2021-34527
Windows Print Spooler Remote Code Execution Vulnerability
17
CVE-2023-23397
Microsoft Outlook Elevation of Privilege Vulnerability
17
CVE-2022-30190
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
13