Open-source detection rules, indexed and cross-referenced.
Sigma, YARA, Suricata, Elastic, Splunk, Falco, Wazuh and more, searchable from one box. One schema across formats, every rule linked back to the file it came from.
Tracked sources
sort
- 01 Azure/Azure-Sentinel 1830
- 02 Bert-JanP/Hunting-Queries-Detection-Rules 449
- 03 chainguard-dev/osquery-defense-kit 270
- 04 chronicle/detection-rules 379
- 05 elastic/detection-rules 1951
- 06 elastic/protections-artifacts 4335
- 07 Emerging Threats Open 50812
- 08 falcosecurity/rules 93
- 09 Neo23x0/signature-base 5903
- 10 panther-labs/panther-analysis 1024
- 11 reversinglabs/reversinglabs-yara-rules 1240
- 12 SigmaHQ/sigma 3783
- 13 socfortress/Wazuh-Rules 2211
- 14 splunk/security_content 2156
- 15 Wazuh Core Ruleset 4420
Newest detections
42580 et-open hidden · include- Suspicious Child Process of PaperCut Server Component elastic-detection-rules 2026-08-28
- Suspicious Java Class File Created in PaperCut Server Library elastic-detection-rules 2026-08-28
- Binfmt Configuration File Creation elastic-detection-rules 2026-08-25
- Suspicious Reading of procfs Syscall File elastic-detection-rules 2026-08-25
- Windows EDRSilencer Custom Outbound Filter Added splunk-security-content 2026-08-23
- Windows Filtering Platform Filter Added To Block EDR Process splunk-security-content 2026-08-23
- First Seen SonicWall Remote Access Login by User and Source elastic-detection-rules 2026-08-21
- Potential Evasion via Boot Time Removal Tool elastic-detection-rules 2026-08-21
- Python Network Traffic During Package Build splunk-security-content 2026-08-21
- Python PTH File Creation During Package Installation splunk-security-content 2026-08-21
- Python PYTHONPATH Modification During Package Installation splunk-security-content 2026-08-21
- Python Site Hooks Creation During Package Installation splunk-security-content 2026-08-21
- Potential DNS Rebinding from Public to Private Address elastic-detection-rules 2026-08-20
- Potential DNS Tunneling via Long and Unique Subdomains elastic-detection-rules 2026-08-20
- Potential Self-Signed TLS Certificate Recently Issued on External Connection elastic-detection-rules 2026-08-20
Most-covered techniques
top 20One technique, every rule mapped to it, grouped by source.
T1190
Exploit Public-Facing Application
6602
T1568
Dynamic Resolution
5929
T1566
Phishing
1794
T1059
Command and Scripting Interpreter
1448
T1071
Application Layer Protocol
1056
T1027
Obfuscated Files or Information
896
T1078
Valid Accounts
729
T1041
Exfiltration Over C2 Channel
713
T1218
System Binary Proxy Execution
631
T1059.001
Command and Scripting Interpreter: PowerShell
521
T1562
Impair Defenses
502
T1098
Account Manipulation
498
T1105
Ingress Tool Transfer
400
T1003
OS Credential Dumping
372
T1548
Abuse Elevation Control Mechanism
361
T1685
Disable or Modify Tools
361
T1021
Remote Services
354
T1055
Process Injection
350
T1059.004
Command and Scripting Interpreter: Unix Shell
349
T1574
Hijack Execution Flow
328