{"adoption": {"forks": 692, "observed_at": "2026-08-28T04:07:11.100432+00:00", "stars": 2693}, "canonical_url": "https://ross.abutalabs.com/products/detection-rules", "card": {"archived": false, "artifact_type": "dataset", "description": null, "domain": ["security"], "enriched": true, "function": ["security", "monitoring", "testing", "parser", "developer-tools"], "health_score": 100, "homepage": "https://www.elastic.co/guide/en/security/current/detection-engine-overview.html", "language": "Python", "license": "NOASSERTION", "license_family": "other", "maturity": "active", "member_repos": ["elastic/detection-rules"], "name": "elastic/detection-rules", "platform": ["python"], "pushed_at": "2026-08-26T20:20:01+00:00", "repo": "elastic/detection-rules", "stars": 2693, "tags": ["detection-rules", "detections-as-code", "siem-rules", "threat-detection-rules", "kql", "rule-validation", "security-analytics", "elastic-stack", "rule-packaging", "adversary-emulation", "threat-detection", "threat-hunting", "siem", "detection-engineering", "elastic-security", "mitre-attack", "kibana"], "topics": ["threat-detection", "threat-hunting"], "urls": [], "use_cases": ["find prebuilt detection rules for elastic security", "manage detections as code pipelines", "validate and test custom detection rules before deployment", "parse and validate kibana query language (kql) queries", "run red team attack simulations (rtas) to test detection coverage", "map detection rule coverage to mitre att&ck techniques", "contribute new threat detection rules to elastic security"], "what_it_is": "The official open-source repository of detection rules used by Elastic Security's Detection Engine, containing thousands of prebuilt threat detection and threat hunting rules. It also ships Python tooling for parsing, validating, testing, and packaging rules, plus a Kibana API client for Detections-as-Code pipelines.", "when_to_avoid": ["you use a siem other than elastic (rules are written for the elastic detection engine and kql)", "you need a general-purpose ids/ips rule format like suricata or sigma without conversion", "you just want to consume rules without engaging with python tooling or kibana apis", "you need managed detection content with vendor support outside the elastic ecosystem"], "when_to_choose": ["you run elastic security and want the latest community-maintained detection rules", "you want to automate deployment of detection rules via ci/cd (detections as code)", "you need python tooling to lint, test, and package detection rules", "you want to validate kql queries programmatically", "you are building threat hunting queries and want a shared library of hunting content"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/detection-rules", "repo": "elastic/detection-rules", "role": "main", "score": 94}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:07:11.100432+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T02:16:31.270015+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "60551d15f645876cc154c3d79071a05302283cebbd5307f6e2793060fe3ffcbf", "fetched_at": "2026-08-28T04:07:11.100432+00:00", "kind": "readme", "missing": false, "url": "https://github.com/elastic/detection-rules"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 99, "longevity": 100, "rhythm": 85}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_license"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 2268, "days_push": 7, "days_rel": 23, "gap_med": 38.5, "n_releases_24m": 13}, "score": 94, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}