Detection Rules

Total Rules

0

Enabled

0
0 disabled

YARA

0

Sigma

0

Add Detection Rule

Nothing is executed. Content is parsed with regex only to surface metadata. YARA rule name & meta: fields and Sigma title/level/logsource are extracted for display.

Filter & Export

⇩ Export enabled YARA (rules.yar) ⇩ Export enabled Sigma (rules.yml)

Tags (0)

No tags yet. Add rules with comma-separated tags to build a filterable index.

Rule Library (0 shown)

TypeNameSeverityMetaTagsAuthorAddedState
No detection rules. Paste a YARA rule or Sigma YAML above to start your library.

About This Library

Detection rules are the behavioral counterpart to the IoCs stored across this platform. Keep the YARA and Sigma content that accompanies your indicators here, toggle rules on/off, and pull a plain-text bundle of everything enabled straight into your scanners & SIEM: rules.yar for a YARA engine, rules.yml for a Sigma pipeline (e.g. sigmac / sigma-cli). Parsing is read-only and best-effort — no rule is ever compiled or executed here.

Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php