Sources
Every indexed ruleset
Each one re-checked hourly. The rules stay in their own repositories, and every entry here points at its upstream file.
Official Microsoft Sentinel community repo — KQL analytics, hunting queries, workbooks, playbooks.
checked
Multi-platform community hunting queries — KQL, Sigma, SPL, ATT&CK-mapped.
checked
Production-ready osquery detection queries organized by ATT&CK technique.
checked
Official Google Chronicle community detection rules in YARA-L 2.0.
checked
Official Elastic SIEM detection rules — TOML wrapping EQL/KQL/Lucene queries, mapped to ATT&CK.
checked
Elastic's malware protection signatures — YARA rules plus behavioral EQL rules.
checked
Proofpoint Emerging Threats Open ruleset — the de facto Suricata community rules. Daily-rebuilt tarball, ~50k rules across malware, exploits, scans, …
checked
Official Falco rules — Kubernetes, containers, Linux syscall events, cloud-native threats.
checked
Florian Roth's YARA rule collection — malware, APT, obfuscation patterns. Heavily referenced.
checked
Python-native Detection-as-Code for Panther — AWS, GCP, Azure, Okta, GitHub, endpoint.
checked
ReversingLabs threat intelligence converted to YARA rules.
checked
Canonical Sigma rule repository — platform-agnostic detections that convert to 40+ SIEMs.
checked
Community Wazuh rules supplementing the default ruleset shipped in Wazuh release packages.
checked
Splunk's official ESCU — SPL searches with YAML metadata, mapped to ATT&CK and Cyber Kill Chain.
checked
The rules shipped with the Wazuh agent. Indexed because the community Wazuh rulesets chain off these SIDs via if_sid.
checked
Adding a source is deliberate rather than open. See about this index for how sources are chosen and how the data is built.