
YARA
Pattern-matching language for identifying and classifying malware. A rule combines text, hex and regex strings with a boolean condition, and is run against files, processes or memory dumps.
.yar .yara

Suricata
Signatures for the Suricata network IDS/IPS engine. Each rule has an action, a header (protocol, addresses, ports, direction) and options that inspect packets, flows and application-layer protocols.
.rules

Sagan
Rules for the Sagan real-time log analysis engine. The grammar is close to Suricata's, but rules match log lines (syslog, …) instead of network packets.
.rules
Sigma
Generic, vendor-neutral signature format for log events, written in YAML. A Sigma rule describes suspicious log entries once and is converted into the query language of any SIEM (Splunk, Elastic, Microsoft Sentinel, …).
.yml .yaml

Splunk SPL
Searches written in Splunk's Search Processing Language, used as correlation searches and detections in Splunk Enterprise Security.
.spl

Elastic
Detection rules for Elastic Security, stored as TOML with an EQL, KQL, Lucene or ES|QL query that runs against an Elasticsearch cluster.
.toml

KQL
Kusto Query Language queries, used as hunting and analytics rules in Microsoft Sentinel, Microsoft Defender XDR and Azure Data Explorer.
.kql

Plum Island
Queries ("antibodies") matched against Plum Island's own Internet-scan index to spot exposed or compromised services.
ATR
Agent Threat Rules: an open YAML detection format for threats against AI agents — prompt injection, tool poisoning, skill compromise, context exfiltration and more, each rule identified as ATR-YYYY-NNNNN.
.yaml .yml

Nmap NSE
Lua scripts for the Nmap Scripting Engine, used to detect services, vulnerabilities and misconfigurations while scanning hosts.
.nse

OWASP CRS
OWASP Core Rule Set: generic attack-detection rules for web application firewalls compatible with ModSecurity (ModSecurity, Coraza, …), covering SQL injection, XSS, remote code execution and more.
.conf
Kunai
YAML detection and filtering rules for Kunai, an eBPF-based Linux threat-hunting agent that records process, file and network events.
.yml .yaml

NOVA
Prompt pattern-matching rules for hunting malicious or abusive prompts sent to LLMs, combining keyword, semantic and LLM-based matching in a YARA-like syntax.
.nov

Wazuh
XML rules for the Wazuh XDR/SIEM platform. Rules match decoded log events and raise alerts with a level, groups and compliance mappings.
.xml

Zeek
Scripts and signatures for the Zeek network security monitor, which turns traffic into rich, structured logs and lets detections react to network events.
.zeek .sig
No format
Rules whose format isn't one of the above — kept on Rulezet as plain text, without format-specific validation.
No format matches your search.