# elastic/detection-rules

Repository: https://github.com/elastic/detection-rules
Canonical: https://ross.abutalabs.com/products/detection-rules
Homepage: https://www.elastic.co/guide/en/security/current/detection-engine-overview.html
Language: Python
License: NOASSERTION
License Family: other
Topics: threat-detection, threat-hunting
Last push: 2026-08-26T20:20:01+00:00

## Health v2 (maintenance only)
Score: 94/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 85, longevity 100
- inputs: {"age_days": 2268, "days_push": 7, "days_rel": 23, "gap_med": 38.5, "n_releases_24m": 13}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2693, forks 692 (observed 2026-08-28T04:07:11.100432+00:00)

## What it is
The official open-source repository of detection rules used by Elastic Security's Detection Engine, containing thousands of prebuilt threat detection and threat hunting rules. It also ships Python tooling for parsing, validating, testing, and packaging rules, plus a Kibana API client for Detections-as-Code pipelines.

## Use cases
- find prebuilt detection rules for elastic security
- manage detections as code pipelines
- validate and test custom detection rules before deployment
- parse and validate kibana query language (kql) queries
- run red team attack simulations (rtas) to test detection coverage
- map detection rule coverage to mitre att&ck techniques
- contribute new threat detection rules to elastic security

## When to choose
- you run elastic security and want the latest community-maintained detection rules
- you want to automate deployment of detection rules via ci/cd (detections as code)
- you need python tooling to lint, test, and package detection rules
- you want to validate kql queries programmatically
- you are building threat hunting queries and want a shared library of hunting content

## When to avoid
- you use a siem other than elastic (rules are written for the elastic detection engine and kql)
- you need a general-purpose ids/ips rule format like suricata or sigma without conversion
- you just want to consume rules without engaging with python tooling or kibana apis
- you need managed detection content with vendor support outside the elastic ecosystem

## Facets
- artifact type: dataset
- maturity: active
- function: security, monitoring, testing, parser, developer-tools
- domain: security
- platform: python
- tags: detection-rules, detections-as-code, siem-rules, threat-detection-rules, kql, rule-validation, security-analytics, elastic-stack, rule-packaging, adversary-emulation, threat-detection, threat-hunting, siem, detection-engineering, elastic-security, mitre-attack, kibana

## Member repositories
- elastic/detection-rules (main) score 94

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:07:11.100432+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:16:31.270015+00:00, confidence not recorded.
  - readme: https://github.com/elastic/detection-rules (fetched 2026-08-28T04:07:11.100432+00:00, sha 60551d15f645)
- Data as of 2026-08-30T08:39:29.467469+00:00.
