Provides a standardized, open-source format and an extensive collection of detection rules for security monitoring across diverse SIEM platforms.
This repository offers over 3000 detection rules in a generic signature format designed for various SIEM systems. It includes different rule types such as `Generic Detection Rules`, `Threat Hunting Rules`, and `Emerging Threat Rules`, categorized within specific directories like `./rules/` and `./rules-threat-hunting/`. Security professionals can use these rules to detect behaviors, techniques, and specific threats across platforms like Splunk and Elastic.
Provides a standardized, open-source format and an extensive collection of detection rules for security monitoring across diverse SIEM platforms.
Security professionals, threat hunters, and detection engineers looking to implement standardized detection logic in their SIEM.