{"id":23106006,"url":"https://github.com/muchdogesec/awesome_detection_rules","last_synced_at":"2026-02-11T09:07:53.766Z","repository":{"id":266958811,"uuid":"884647725","full_name":"muchdogesec/awesome_detection_rules","owner":"muchdogesec","description":"A curated list of Awesome Detection Rules","archived":false,"fork":false,"pushed_at":"2024-12-07T08:54:27.000Z","size":6,"stargazers_count":2,"open_issues_count":0,"forks_count":1,"subscribers_count":1,"default_branch":"main","last_synced_at":"2025-10-30T10:01:08.417Z","etag":null,"topics":["detection-engineering","detection-rules","infosec","siem","threat-intel","threat-intelligence","xdr"],"latest_commit_sha":null,"homepage":"https://siemrules.com/","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/muchdogesec.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-11-07T06:12:42.000Z","updated_at":"2025-09-12T07:34:01.000Z","dependencies_parsed_at":"2024-12-07T09:35:26.364Z","dependency_job_id":null,"html_url":"https://github.com/muchdogesec/awesome_detection_rules","commit_stats":null,"previous_names":["muchdogesec/awesome_detection_rules"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/muchdogesec/awesome_detection_rules","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muchdogesec%2Fawesome_detection_rules","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muchdogesec%2Fawesome_detection_rules/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muchdogesec%2Fawesome_detection_rules/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muchdogesec%2Fawesome_detection_rules/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/muchdogesec","download_url":"https://codeload.github.com/muchdogesec/awesome_detection_rules/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/muchdogesec%2Fawesome_detection_rules/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29330858,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-11T06:13:03.264Z","status":"ssl_error","status_checked_at":"2026-02-11T06:12:55.843Z","response_time":97,"last_error":"SSL_read: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["detection-engineering","detection-rules","infosec","siem","threat-intel","threat-intelligence","xdr"],"created_at":"2024-12-17T00:56:23.294Z","updated_at":"2026-02-11T09:07:53.749Z","avatar_url":"https://github.com/muchdogesec.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# Awesome Detection Rules\n\nA curated list of detection rule sources.\n\nWe built this during our research for [SIEM Rules, your detection engineering AI assistant](https://www.siemrules.com/).\n\n[You can find a copy of the following table in a GSheet here](https://docs.google.com/spreadsheets/d/1-vmQXxTigdF37-qZhwvpWwCBO4iU4mA-eq2iKtpUSjg/edit?usp=sharing).\n\n\u003ctable\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eDescription\u003c/td\u003e\n        \u003ctd\u003eURL\u003c/td\u003e\n        \u003ctd\u003eLanguage\u003c/td\u003e\n        \u003ctd\u003eProduct\u003c/td\u003e\n        \u003ctd\u003eSummary\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eElastic Detection Rules\u003c/td\u003e\n        \u003ctd\u003ehttps://github.com/elastic/detection-rules\u003c/td\u003e\n        \u003ctd\u003eQuery DSL\u003c/td\u003e\n        \u003ctd\u003eElastic\u003c/td\u003e\n        \u003ctd\u003eThe Elastic Detection Rules repository on GitHub provides rules for identifying threats using Elastic\u0026#39;s Query DSL, organized by domains like malware, endpoint, and cloud.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eChronicle Detection Rules\u003c/td\u003e\n        \u003ctd\u003ehttps://github.com/chronicle/detection-rules\u003c/td\u003e\n        \u003ctd\u003eYARA-L 2.0\u003c/td\u003e\n        \u003ctd\u003eChronicle\u003c/td\u003e\n        \u003ctd\u003eThis repository contains detection rules written in YARA-L 2.0 for Chronicle Security\u0026#39;s platform, focused on threat detection for diverse environments.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eSigma Rules\u003c/td\u003e\n        \u003ctd\u003ehttps://github.com/SigmaHQ/sigma\u003c/td\u003e\n        \u003ctd\u003eSigma\u003c/td\u003e\n        \u003ctd\u003eSigma\u003c/td\u003e\n        \u003ctd\u003eThe Sigma Rules repository on GitHub contains a curated list of Sigma rules structured by domain (e.g., Windows, network), enabling cross-platform detections.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eAnvilogic Armory\u003c/td\u003e\n        \u003ctd\u003ehttps://github.com/anvilogic-forge/armory\u003c/td\u003e\n        \u003ctd\u003eSigma\u003c/td\u003e\n        \u003ctd\u003eAnvilogic\u003c/td\u003e\n        \u003ctd\u003eAnvilogic Armory provides a collection of Sigma-based detection rules that can be used for cross-platform threat detection across different security platforms.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003ePanther Labs\u003c/td\u003e\n        \u003ctd\u003ehttps://github.com/panther-labs/panther-analysis/tree/develop/rules\u003c/td\u003e\n        \u003ctd\u003ePython\u003c/td\u003e\n        \u003ctd\u003ePanther\u003c/td\u003e\n        \u003ctd\u003ePanther Labs offers Python-based detection rules in this repository, designed for security operations teams using Panther to detect threats in cloud and hybrid environments.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eSplunk Security Content\u003c/td\u003e\n        \u003ctd\u003ehttps://github.com/splunk/security_content\u003c/td\u003e\n        \u003ctd\u003eSPL\u003c/td\u003e\n        \u003ctd\u003eSplunk\u003c/td\u003e\n        \u003ctd\u003eThe Splunk Security Content repository provides SPL-based detection rules and analytic stories for security use cases, including endpoint, cloud, and threat intelligence.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eDatadog Security Rules\u003c/td\u003e\n        \u003ctd\u003ehttps://docs.datadoghq.com/security/default_rules/\u003c/td\u003e\n        \u003ctd\u003eProprietary Syntax\u003c/td\u003e\n        \u003ctd\u003eDatadog\u003c/td\u003e\n        \u003ctd\u003eDatadog\u0026#39;s Security Rules documentation includes default security detection rules for use with Datadog’s SIEM, allowing users to build custom queries for their needs.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eSekoia Detection Rules\u003c/td\u003e\n        \u003ctd\u003ehttps://docs.sekoia.io/xdr/features/detect/built_in_detection_rules/\u003c/td\u003e\n        \u003ctd\u003eProprietary Syntax\u003c/td\u003e\n        \u003ctd\u003eSekoia\u003c/td\u003e\n        \u003ctd\u003eSekoia\u0026#39;s built-in detection rules cover a variety of security events and offer pre-defined logic for detecting threats across environments.\u003c/td\u003e\n    \u003c/tr\u003e\n    \u003ctr\u003e\n        \u003ctd\u003eExabeam Content\u003c/td\u003e\n        \u003ctd\u003ehttps://github.com/ExabeamLabs/Content-Doc\u003c/td\u003e\n        \u003ctd\u003eJSON-based Rules\u003c/td\u003e\n        \u003ctd\u003eExabeam\u003c/td\u003e\n        \u003ctd\u003eExabeam Content repository contains JSON-based detection content designed for Exabeam’s SIEM, covering various security events and threat intelligence use cases.\u003c/td\u003e\n    \u003c/tr\u003e\n\u003c/table\u003e\n\n## Contributing\n\nFeel free to [contribute](CONTRIBUTING.md).\n\n## Join the community\n\n[Join the DOGESEC community](https://community.dogesec.com/).\n\n## License\n\n[Creative Commons Attribution 4.0 International Public License](LICENSE).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmuchdogesec%2Fawesome_detection_rules","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fmuchdogesec%2Fawesome_detection_rules","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fmuchdogesec%2Fawesome_detection_rules/lists"}