Ross ROSS = Recommend OSS · open-source software intelligence for agents

socfortress/Wazuh-Rules resource

Advanced Wazuh Rules for more accurate threat detection. Feel free to implement within your own Wazuh environment, contribute, or fork! observed · 2026-08-28

github.com/socfortress/Wazuh-Rules · homepage · Python observed · 2026-08-28

Health v2 · maintenance only

55/100

  • Activity 71
  • Release rhythm 8
  • Longevity 100

Flags: no_license

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1489
  • days_rel: n/a
  • days_push: 175
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1381 stars · 317 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A community-maintained collection of advanced Wazuh detection rulesets that improve on Wazuh's default rules for more accurate threat detection. It is maintained by SOCFortress and intended to be dropped into an existing Wazuh SIEM environment.

Use cases

  • improve wazuh threat detection accuracy
  • find better detection rules for my wazuh siem
  • reduce false positives in wazuh alerts
  • get community rulesets for open-source siem
  • detect threats with wazuh edr agent
  • enrich wazuh alerts with more descriptive rules

When to choose

  • you already run Wazuh and find the default ruleset too lax
  • you want a free, community-driven, regularly updated ruleset
  • you want more descriptive and enriched alerts from various log sources and integrations

When to avoid

  • you don't use Wazuh or an open-source SIEM
  • you need a supported, licensed enterprise detection product with vendor guarantees
  • you need rules for a different SIEM like Splunk or Elastic

Facets

dataset · maturity active

security monitoring alerting security monitoring self-hosted wazuh siem detection-rules threat-detection edr soc log-analysis ruleset devops linux docker

2 sources

Member repositories

RepositoryRoleHealth v2
socfortress/Wazuh-Rulesmain55

For agents

markdown · JSON · MCP: product_card(name="socfortress/Wazuh-Rules")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem