Legal
Terms of use
Last updated 11 August 2026.
What this site is
detections.org is a free, read-only index of open-source and freely available detection rules. It exists so that detection engineers can search across rulesets that would otherwise have to be cloned and parsed one at a time.
It is not a SIEM. It does not ingest your logs, run detections, or raise alerts.
The rules are not ours
Every detection indexed here belongs to the project that published it and remains under that project's license. We reproduce rule content only where the upstream license permits, and each source's license is reproduced in full on its own page, linked from every rule.
Where a source publishes no license, we index its metadata and link upstream without reproducing the rule logic.
Nothing on this site grants you rights in any rule. Before deploying, modifying, or redistributing a rule, read the license of the project that published it.
No warranty
The index is provided as is. Detection rules are heuristics written by third parties for environments that are not yours; a rule that is accurate upstream may be noisy, incomplete, or wrong in your estate. Parsing and normalization across fifteen source formats can also introduce errors of our own.
Do not treat anything here as security advice, and do not deploy a rule to production on the strength of this site alone. Verify against the upstream source, which is linked from every page.
Acceptable use
Browse, search, and link freely. Automated bulk scraping is not welcome — it costs us real money and the underlying rules are already available from their source repositories, which is where you should get them.
Corrections and takedowns
If you maintain a project indexed here and want its licensing corrected, its attribution changed, or its content removed, write to contact@detections.org and we will act on it. We would rather hear from you than guess.
Changes
These terms will change as the site grows, particularly once accounts and community notes exist. The date at the top reflects the current version.
See also the privacy policy.