Open Source Detection Library

Detection Rules

Cross-platform SIEM & EDR detection rules
mapped to MITRE ATT&CK framework

Download Β· Import Β· Detect

Sigma Β· Elastic Β· Splunk Β· Sentinel Β· Wazuh Β· Carbon Black Β· CrowdStrike Β· SentinelOne Β· Falco

⭐ GitHub πŸ“¦ Download 🎯 Coverage πŸ—ΊοΈ Navigator
Platforms

9 Platforms Supported

Setiap rule di-maintain per platform native. Download Sigma, atau ambil versi pre-converted untuk SIEM Anda.

MITRE ATT&CK

Coverage Matrix

Teknik MITRE ATT&CK yang ter-cover. Search, filter, dan identifikasi gap.

IDTechniqueTactic Ξ£ELKSPL KQLWZHCB FLCS1FAL Cov
Resources

Documentation & Tools

πŸ“– README
Quick-start per platform, naming convention, MITRE tagging guide.
🀝 Contributing
Standards, PR template, CI checklist, validation commands.
βš–οΈ Quality Framework
Rule fidelity classification: informational β†’ critical.
πŸ§ͺ Atomic Testing
Atomic Red Team mapping for rule verification.
πŸ“ Changelog
Version history, breaking changes, migration notes.
πŸ“¦ Latest Release
Pre-built ZIP with auto-translated Sigma β†’ all backends.