Downloads
Detection rule packs
26 ready-to-deploy packs · built 20260616-2347
The full Sigma detection corpus, machine-converted to each SIEM and EDR query language and packaged to deploy. Pick your platform below and import the pack straight into your tooling. The corpora we did not author - YARA, Falco, Suricata, MITRE CAR, and the raw Sigma YAML - are linked to their upstream sources rather than re-hosted.
◈
Ready-to-deploy packs
26 platformsClickHouse
Download .zipCrowdStrike LogScale
Download .zipDatadog Cloud SIEM
Download .zipElastAlert
Download .zipElastic (Lucene)
Download .zipElastic EQL
Download .zipElastic ES|QL
Download .zipGoogle SecOps / Chronicle
Download .zipGrafana Loki (LogQL)
Download .zipIBM QRadar (AQL)
Download .zipLogpoint
Download .zipMicrosoft Sentinel / Defender (KQL)
Download .zipNetWitness
Download .zipOpenSearch (Lucene)
Download .zipOpenSearch (PPL)
Download .zipPalo Alto Cortex XDR
Download .zipPanther
Download .zipQuickwit
Download .zipRapid7 InsightIDR
Download .zipSentinelOne (Deep Visibility)
Download .zipSentinelOne (PowerQuery)
Download .zipSplunk SPL
Download .zipSplunk SPL2
Download .zipSumo Logic CSE
Download .zipSumo Logic CSE Rule
Download .zipVMware Carbon Black
Download .zipEach pack holds one file per rule in the target query language, plus a NOTICE with attribution. Map field names to your log schema and tune thresholds before you trust an alert.
◈
From the source
5 upstreamSigmaHQ Detection Rules
Get from sourceFlorian Roth signature-base YARA rules
Get from sourceFalco Runtime Detection Rules
Get from sourceProofpoint Suricata ET-Open Ruleset
Get from sourceMITRE Cyber Analytics Repository
Get from sourceWe link these rather than re-host them: they are served free upstream and their licenses are cleanest at the source.