Every open-source detection rule, indexed.
Search Sigma, YARA, Elastic, Splunk, Falco, Panther, Wazuh, Chronicle and osquery — one schema across formats, linked back to upstream.
Tracked sources
sort
- 01 Azure/Azure-Sentinel 1827
- 02 Bert-JanP/Hunting-Queries-Detection-Rules 449
- 03 chainguard-dev/osquery-defense-kit 270
- 04 chronicle/detection-rules 379
- 05 elastic/detection-rules 1940
- 06 elastic/protections-artifacts 4335
- 07 Emerging Threats Open 50695
- 08 falcosecurity/rules 93
- 09 Neo23x0/signature-base 5903
- 10 panther-labs/panther-analysis 1024
- 11 reversinglabs/reversinglabs-yara-rules 1240
- 12 SigmaHQ/sigma 3783
- 13 socfortress/Wazuh-Rules 2211
- 14 splunk/security_content 2155
- 15 Wazuh Core Ruleset 4420
Newest detections
42550 et-open hidden · include- Python Network Traffic During Package Build splunk-security-content 2026-08-21
- Python PTH File Creation During Package Installation splunk-security-content 2026-08-21
- Python PYTHONPATH Modification During Package Installation splunk-security-content 2026-08-21
- Python Site Hooks Creation During Package Installation splunk-security-content 2026-08-21
- File Downloaded by Curl/Wget and Piped to Interpreter elastic-detection-rules 2026-08-19
- PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy sigmahq-sigma 2026-08-19
- Process Execution Followed by Self-Deletion elastic-detection-rules 2026-08-19
- Windows Alternate Data Stream Created Over Local Share splunk-security-content 2026-08-19
- Windows Cloud Sensitive File Read Access By Uncommon Process splunk-security-content 2026-08-19
- Windows Defender MpClient.dll Loaded by Non-Defender Process splunk-security-content 2026-08-19
- Bun Script Attempted to Access IMDS Metadata elastic-protections-artifacts 2026-08-18
- Bun Script Attempted to Access IMDS Metadata elastic-protections-artifacts 2026-08-18
- Potential ClickFix Attack via Windows Terminal elastic-protections-artifacts 2026-08-18
- Potential Cloud Credential Harvesting via Bun elastic-protections-artifacts 2026-08-18
- Potential Cloud Credential Harvesting via Bun elastic-protections-artifacts 2026-08-18
Most-covered techniques
top 20Pivot to every rule across the index that addresses a technique.
T1190
Exploit Public-Facing Application
6581
T1568
Dynamic Resolution
5929
T1566
Phishing
1795
T1059
Command and Scripting Interpreter
1446
T1071
Application Layer Protocol
1048
T1027
Obfuscated Files or Information
896
T1078
Valid Accounts
728
T1041
Exfiltration Over C2 Channel
713
T1218
System Binary Proxy Execution
631
T1059.001
Command and Scripting Interpreter: PowerShell
520
T1562
Impair Defenses
498
T1098
Account Manipulation
495
T1105
Ingress Tool Transfer
400
T1003
OS Credential Dumping
372
T1548
Abuse Elevation Control Mechanism
361
T1685
Disable or Modify Tools
359
T1021
Remote Services
354
T1055
Process Injection
350
T1059.004
Command and Scripting Interpreter: Unix Shell
349
T1574
Hijack Execution Flow
328