Skip to content

Rule Creator

A guided GUI for authoring detection rules across three formats:

  • Sigma — generic SIEM detection rules.
  • Yara — pattern-matching rules for identifying and classifying files/malware.
  • Snort/Suricata — network intrusion detection rules.

Useful for turning an investigation’s findings — an IOC from IOC Tools, a pattern spotted in Email Analyzer, a technique tagged by Newsfeed — into something you can actually deploy, without hand-writing rule syntax from scratch.