[[ fm.text ]] Click here

Rule Formats 16

Every detection-rule format hosted on Rulezet: what it is for, who maintains it, and where to find its official documentation.

Rulezet hosts the format Export available for every format (JSON, MISP, STIX) Format-specific conversion
#1
YARA
YARA Files & memory · VirusTotal

Pattern-matching language for identifying and classifying malware. A rule combines text, hex and regex strings with a boolean condition, and is run against files, processes or memory dumps.

Rules 505,902
Files .yar .yara
Testable on Rulezet
#2
Suricata
SURICATA Network · OISF

Signatures for the Suricata network IDS/IPS engine. Each rule has an action, a header (protocol, addresses, ports, direction) and options that inspect packets, flows and application-layer protocols.

Rules 99,000
Files .rules
#3
Sagan
SAGAN Logs & SIEM · Quadrant Information Security

Rules for the Sagan real-time log analysis engine. The grammar is close to Suricata's, but rules match log lines (syslog, …) instead of network packets.

Rules 17,525
Files .rules
#4
Sigma
SIGMA Logs & SIEM · SigmaHQ

Generic, vendor-neutral signature format for log events, written in YAML. A Sigma rule describes suspicious log entries once and is converted into the query language of any SIEM (Splunk, Elastic, Microsoft Sentinel, …).

Rules 8,029
Files .yml .yaml
Testable on Rulezet
#5
Splunk SPL
SPLUNK Logs & SIEM · Splunk

Searches written in Splunk's Search Processing Language, used as correlation searches and detections in Splunk Enterprise Security.

Rules 2,452
Files .spl
#6
Elastic
ELASTIC Logs & SIEM · Elastic

Detection rules for Elastic Security, stored as TOML with an EQL, KQL, Lucene or ES|QL query that runs against an Elasticsearch cluster.

Rules 2,091
Files .toml
#7
KQL
KQL Logs & SIEM · Microsoft

Kusto Query Language queries, used as hunting and analytics rules in Microsoft Sentinel, Microsoft Defender XDR and Azure Data Explorer.

Rules 1,050
Files .kql
#8
Plum Island
PLUM Internet scanning · D4 Project (CIRCL)

Queries ("antibodies") matched against Plum Island's own Internet-scan index to spot exposed or compromised services.

Rules 926
#9
ATR
ATR AI agents · Agent Threat Rules project

Agent Threat Rules: an open YAML detection format for threats against AI agents — prompt injection, tool poisoning, skill compromise, context exfiltration and more, each rule identified as ATR-YYYY-NNNNN.

Rules 770
Files .yaml .yml
Testable on Rulezet
#10
Nmap NSE
NSE Scanning · Nmap Project

Lua scripts for the Nmap Scripting Engine, used to detect services, vulnerabilities and misconfigurations while scanning hosts.

Rules 618
Files .nse
Testable on Rulezet
#11
OWASP CRS
CRS Web application · OWASP

OWASP Core Rule Set: generic attack-detection rules for web application firewalls compatible with ModSecurity (ModSecurity, Coraza, …), covering SQL injection, XSS, remote code execution and more.

Rules 415
Files .conf
#12
Kunai
KUNAI Endpoint (Linux) · Kunai Project

YAML detection and filtering rules for Kunai, an eBPF-based Linux threat-hunting agent that records process, file and network events.

Rules 334
Files .yml .yaml
#13
NOVA
NOVA AI / LLM prompts · NOVA Framework

Prompt pattern-matching rules for hunting malicious or abusive prompts sent to LLMs, combining keyword, semantic and LLM-based matching in a YARA-like syntax.

Rules 69
Files .nov
#14
Wazuh
WAZUH Logs & SIEM · Wazuh

XML rules for the Wazuh XDR/SIEM platform. Rules match decoded log events and raise alerts with a level, groups and compliance mappings.

Rules 29
Files .xml
#15
Zeek
ZEEK Network · Zeek Project

Scripts and signatures for the Zeek network security monitor, which turns traffic into rich, structured logs and lets detections react to network events.

Rules 3
Files .zeek .sig
No format
NO FORMAT Other

Rules whose format isn't one of the above — kept on Rulezet as plain text, without format-specific validation.

Rules 0

No format matches your search.