Ross ROSS = Recommend OSS · open-source software intelligence for agents

elastic/detection-rules resource

None observed · 2026-08-28

github.com/elastic/detection-rules · homepage · Python · NOASSERTION (other) observed · 2026-08-28

Health v2 · maintenance only

94/100

  • Activity 99
  • Release rhythm 85
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 38.5
  • age_days: 2268
  • days_rel: 23
  • days_push: 7
  • n_releases_24m: 13

Full methodology

Adoption not part of the score

2693 stars · 692 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

The official open-source repository of detection rules used by Elastic Security's Detection Engine, containing thousands of prebuilt threat detection and threat hunting rules. It also ships Python tooling for parsing, validating, testing, and packaging rules, plus a Kibana API client for Detections-as-Code pipelines.

Use cases

  • find prebuilt detection rules for elastic security
  • manage detections as code pipelines
  • validate and test custom detection rules before deployment
  • parse and validate kibana query language (kql) queries
  • run red team attack simulations (rtas) to test detection coverage
  • map detection rule coverage to mitre att&ck techniques
  • contribute new threat detection rules to elastic security

When to choose

  • you run elastic security and want the latest community-maintained detection rules
  • you want to automate deployment of detection rules via ci/cd (detections as code)
  • you need python tooling to lint, test, and package detection rules
  • you want to validate kql queries programmatically
  • you are building threat hunting queries and want a shared library of hunting content

When to avoid

  • you use a siem other than elastic (rules are written for the elastic detection engine and kql)
  • you need a general-purpose ids/ips rule format like suricata or sigma without conversion
  • you just want to consume rules without engaging with python tooling or kibana apis
  • you need managed detection content with vendor support outside the elastic ecosystem

Facets

dataset · maturity active

security monitoring testing parser developer-tools security python detection-rules detections-as-code siem-rules threat-detection-rules kql rule-validation security-analytics elastic-stack rule-packaging adversary-emulation threat-detection threat-hunting siem detection-engineering elastic-security mitre-attack kibana

1 source

Member repositories

RepositoryRoleHealth v2
elastic/detection-rulesmain94

For agents

markdown · JSON · MCP: product_card(name="elastic/detection-rules")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem