Sources

Every indexed ruleset

Fifteen open-source detection projects. Each one is cloned, parsed into a common shape, and re-indexed hourly — the rules themselves stay in their own repositories.

Official Microsoft Sentinel community repo — KQL analytics, hunting queries, workbooks, playbooks.

1797 rules
MIT

Multi-platform community hunting queries — KQL, Sigma, SPL, ATT&CK-mapped.

422 rules

Production-ready osquery detection queries organized by ATT&CK technique.

164 rules

Official Google Chronicle community detection rules in YARA-L 2.0.

379 rules

Official Elastic SIEM detection rules — TOML wrapping EQL/KQL/Lucene queries, mapped to ATT&CK.

1931 rules

Elastic's malware protection signatures — YARA rules plus behavioral EQL rules.

4334 rules

Proofpoint Emerging Threats Open ruleset — the de facto Suricata community rules. Daily-rebuilt tarball, ~50k rules across malware, exploits, scans, …

31538 rules

Official Falco rules — Kubernetes, containers, Linux syscall events, cloud-native threats.

93 rules

Florian Roth's YARA rule collection — malware, APT, obfuscation patterns. Heavily referenced.

5903 rules

Python-native Detection-as-Code for Panther — AWS, GCP, Azure, Okta, GitHub, endpoint.

905 rules

ReversingLabs threat intelligence converted to YARA rules.

1240 rules
MIT

Canonical Sigma rule repository — platform-agnostic detections that convert to 40+ SIEMs.

3720 rules

Community Wazuh rules supplementing the default ruleset shipped in Wazuh release packages.

1950 rules

Splunk's official ESCU — SPL searches with YAML metadata, mapped to ATT&CK and Cyber Kill Chain.

2155 rules

The rules shipped with the Wazuh agent. Indexed because the community Wazuh rulesets chain off these SIDs via if_sid.

3715 rules

Adding a source is deliberate rather than open — see about this index for how sources are chosen and how the data is built.

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.