[[ fm.text ]] Click here

Why Rulezet

The community platform to publish, validate, improve and deploy detection rules — one versioned, searchable catalogue instead of files scattered across repositories, wikis and inboxes.

639,213Rules
15Formats
13Bundles
146Members

The problem

Why detection rule sharing needs a platform of its own.

Scattered

Rules live in hundreds of repositories, blog posts and private folders, each with its own conventions.

Unchecked

Nothing tells you a rule still parses, duplicates another one, or was changed upstream.

No feedback loop

False positives and fixes found by one team rarely make it back to the author or to others.

Rulezet gathers rules of every format in one place, validates them, keeps their history, lets the community improve them together, and sends them back to the tools that run them. Read more in the documentation.

How it works

The life of a rule on Rulezet.

  1. 1
    Bring it in

    Write it, upload files, or import a whole GitHub repository.

  2. 2
    Validated

    Parsed by its format, checked for duplicates, given a quality score.

  3. 3
    Improved together

    Comments, edit proposals and reviews; every change versioned.

  4. 4
    Deployed

    Exported or converted, pushed to MISP or Velociraptor, pulled by API.

Share & import

Bring rules in from wherever they live today, keep one versioned copy, give it back to everyone.

Create, upload or paste

Publish a rule in a few seconds, from scratch or from files you already have.

  • Editor with syntax highlighting for every format, plus Markdown for the description
  • Upload single files or a whole zip; import a Rulezet JSON export as is
  • Every rule gets TLP:CLEAR and PAP:CLEAR by default, then any tag you add
  • Each save is a new version, attributed to its author

GitHub import & sync

Index a public repository once, then follow it.

  • Imports every rule it recognises, with the source repository and path kept on the rule
  • Checks the repository again later and shows what changed upstream
  • Changes are reviewed and accepted one by one or in bulk — nothing is overwritten silently
  • Synchronisation can be scheduled

Bundles

Curated collections: a ready-to-deploy pack for a threat, a product or a team.

  • Pick rules from the whole catalogue, of any format
  • Arrange them in folders with the drag-and-drop structure editor
  • Tags, description, comments and votes, like a rule
  • Downloaded in one go, structure included

Rulesets on GitHub

The public catalogue, mirrored to a Git repository.

  • One folder per format, one file per rule
  • Clone it, diff it, pull it from any tool that reads Git
  • Updated automatically from the platform

Quality

A shared rule is only useful if it parses, is not a copy of another one and its history is known.

Validation per format

Every format has its own parser; broken rules never pass unnoticed.

  • Syntax checked on creation, edit and import, with the parser's error message
  • Rules that fail are listed with their error until someone fixes them
  • Fix a rule in place and validate it again in one step
  • A quality score per rule: metadata, references, ATT&CK mapping…

Duplicates & similar rules

The catalogue grows in coverage, not in copies.

  • Content similarity computed between rules of the same format
  • Each rule page lists its closest rules
  • Admins review and merge duplicates across sources

History & audit trail

Who changed what, when — for every rule and across the platform.

  • Every version kept, compared side by side with a diff
  • Metadata changes (tags, owner, description…) listed field by field
  • Platform-wide activity log for administrators

Formats, documented

What each format is for, who maintains it, and what Rulezet can turn it into.

  • YARA, Sigma, Suricata, Zeek, Wazuh, KQL, Splunk, Elastic and more
  • Official site and documentation of each format
  • A graph of every export and conversion

Collaboration

Rules get better the way code does: through review.

Edit proposals

Suggest a change to someone else's rule — like a pull request.

  • The owner sees the exact diff and the reason for the change
  • Discussion on the proposal before it is accepted or declined
  • Accepted changes become a new version, credited to the proposer

Comments & reactions

Discuss a rule or a bundle where it lives.

  • Threaded replies and reactions
  • Report abusive content; moderation by administrators
  • Every discussion of the platform in one hub

Ownership requests

Imported a rule you actually wrote? Ask for it back.

  • Request ownership of a rule from its page
  • An administrator reviews the request and transfers the rule

Contributors

Recognition for the people behind the rules.

  • Public profiles with each member's rules and activity
  • A leaderboard of contributions

Organize & follow

Find the right rule fast, keep your own working space, hear about what matters to you.

Tags, taxonomies & galaxies

Classify rules with the vocabularies the CTI community already uses.

  • MISP taxonomies (TLP, PAP, …) and galaxies (threat actors, malware, tools…)
  • Your own tags on top
  • Filter and search the catalogue by any of them; tag thousands of rules in one job

MITRE ATT&CK

See what is covered and where the gaps are.

  • Rules mapped to ATT&CK techniques
  • Heatmap of the community's coverage across the matrix
  • Filter the catalogue by technique

Workspaces & dashboard

A private space per investigation, and a home page made of the widgets you choose.

  • Workspaces gather rules, bundles, notes, files and reference links
  • Dashboard widgets arranged by drag and drop

Alerts & notifications

"Tell me when…" — without checking the site every day.

  • Alerts on new or changed rules matching your criteria
  • In the app, or by email — instantly or as a daily / weekly digest
  • Notifications for proposals, comments and requests on your rules

Integration

Rules don't stay on a website: they go where detection actually happens.

Export & convert

Every rule, in the shape your tools expect.

  • Native file, Rulezet JSON, MISP object or event, STIX 2.1
  • Velociraptor artifact for YARA and Sigma rules
  • Sigma converted to Splunk, Elastic, Microsoft Sentinel, Sumo Logic, Google SecOps and Loki

MISP & Velociraptor

From the rule page straight to your own tools.

  • Push a rule to your MISP instance
  • Deploy it to endpoints through your Velociraptor server

Federation

Run your own instance and stay in sync with others.

  • Pull rules from a partner Rulezet instance
  • Matched by UUID; skip existing rules or update them in place

REST API & feeds

Everything scriptable.

  • Documented REST API (Swagger), authenticated with an API key
  • Suricata rules served as a feed for suricata-update
Rulezy

AI assistant — Rulezy

Runs on a local model (Ollama): nothing leaves the instance. Each capability is enabled by the instance's administrators.

Rule analysis

Explains what a rule detects, its blind spots and false-positive risks, and how to tune it.

Rule fixer

Proposes a corrected version of a rule that fails validation, shown as a diff.

Rule generator

Drafts a rule in the format you choose from a description, IOCs or a report.

Chat

Answers questions about Rulezet, a format or a rule, from any page.

Open source, self-hostable

Use rulezet.org, or run your own instance.

AGPL-3.0

Developed in the open: read the code, audit it, contribute.

GitHub repository
Your own instance

For a team, a company or a sector — private, or federated with others.

Installation
By CIRCL

Built by CIRCL within the NGSOTI project, next to MISP and its other open tools.

About the project

Get started

Browse what the community already published, or share your first rule.

Rulezet v1.7.4