Rules are shared, validated, reviewed and grouped into bundles — what Rulezet does today.
The Lab proves what each rule detects on reference data, and scores it.
Connectors deliver curated sets to the real tools, natively.
Sightings and production counters flow back and improve the rules.
Code health — a full review of the codebase
A lighter, faster codebase that every other feature builds on — and that is easy to contribute to.
- Performance: hunt down slow pages and endpoints — N+1 queries, missing indexes, heavy serialisation in lists, work that belongs in background jobs or the cache
- Duplication: the same logic written several times (web routes vs API, per-feature helpers, copied tables, badges and dialogs) factored into shared helpers and components
- Size: split the largest files by responsibility — the rule blueprint and core, the job handlers, the models, the biggest templates and components
- Dead code removed, one consistent way to do each thing (permissions, pagination, errors, logs), the new test suite finished and run in CI
- Shipped feature by feature — never a big-bang rewrite
Sightings — "I saw this rule fire"
The signal that is missing today: does this rule work in real life?
- Report in one click or through the API: true positive, false positive (with the kind of environment), deployed in production
- Feeds the quality score, "most deployed" and "noisiest" sorts, and nudges towards a note or an edit proposal when false positives pile up
- Rule and bundle pages show it: "deployed by 14 teams, 3 false-positive reports"
CVE response kit
When a critical vulnerability drops, every rule for it — in hours, in one place.
- A page per CVE: every linked rule across formats, and the gaps ("no Sigma rule yet")
- One-click AI drafts for the missing formats, a ready-made bundle to download or subscribe to
- An alert when a new rule for it is published — built with Vulnerability-Lookup
Connectors per format
Rulezet becomes the place your tools get their rules from — and learn from.
- Deliver: a curated bundle, release or workspace reaches the tool natively — a feed, an API push, a package
- Verify: the tool itself checks what was deployed (does it load on this version?) and reports back
- Learn: anonymous counters from production improve the rules
- Suricata first: a global suricata-update feed already exists; next, a feed per bundle without the rules failing the health checks
Rulezet Lab
Prove what each rule detects, before it reaches production — and give it a score.
- Per format, a controlled environment: replayed network captures, known malware and known-clean files, attack logs
- Detection, false positives and cost measured for every rule and every version — regressions caught automatically
- A Lab score on each rule, added to its quality score
- Replaces the current Rule Tester, which will be deprecated
rulezet-validate GitHub Action
Rulezet inside the repositories where teams keep their detection rules as code.
- Every pull request validated with Rulezet's own parsers and health checks — syntax, duplicate ids, missing dependencies
- Annotations directly on the diff; optional publication to a bundle on merge
Coverage gap analysis
From "searching rules" to "knowing what to deploy".
- Describe your context — sector, threats targeting you (an APT group, a MISP event, a report), your stack
- See which ATT&CK techniques are covered and which are not, per format
- Get a recommended bundle and AI drafts to fill the gaps
Cross-format rule families
One threat, every format: "what do I use in my tool?"
- Equivalent Suricata, Sigma and YARA rules linked into one family
- Sigma converted to SIEM queries: "also available for Splunk, Elastic, Sentinel"
Signed releases & verified publishers
Trust for automated deployment.
- Bundle releases and feeds signed with the publisher's key
- A verified-publisher badge for organisations and trusted contributors
- Required as soon as sensors pull rules automatically
Have an idea, or want to help?
The roadmap is discussed in the open. Suggest a feature, comment on one, or pick one up.
Rulezet v1.7.4