# socfortress/Wazuh-Rules

Advanced Wazuh Rules for more accurate threat detection. Feel free to implement within your own Wazuh environment, contribute, or fork!

Repository: https://github.com/socfortress/Wazuh-Rules
Canonical: https://ross.abutalabs.com/products/wazuh-rules
Homepage: https://www.socfortress.co
Language: Python
License Family: other
Last push: 2026-03-11T08:43:21+00:00

## Health v2 (maintenance only)
Score: 55/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 71, release rhythm 8, longevity 100
- inputs: {"age_days": 1489, "days_push": 175, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1381, forks 317 (observed 2026-08-28T04:04:33.902472+00:00)

## What it is
A community-maintained collection of advanced Wazuh detection rulesets that improve on Wazuh's default rules for more accurate threat detection. It is maintained by SOCFortress and intended to be dropped into an existing Wazuh SIEM environment.

## Use cases
- improve wazuh threat detection accuracy
- find better detection rules for my wazuh siem
- reduce false positives in wazuh alerts
- get community rulesets for open-source siem
- detect threats with wazuh edr agent
- enrich wazuh alerts with more descriptive rules

## When to choose
- you already run Wazuh and find the default ruleset too lax
- you want a free, community-driven, regularly updated ruleset
- you want more descriptive and enriched alerts from various log sources and integrations

## When to avoid
- you don't use Wazuh or an open-source SIEM
- you need a supported, licensed enterprise detection product with vendor guarantees
- you need rules for a different SIEM like Splunk or Elastic

## Facets
- artifact type: dataset
- maturity: active
- function: security, monitoring, alerting
- domain: security, monitoring
- platform: self-hosted
- tags: wazuh, siem, detection-rules, threat-detection, edr, soc, log-analysis, ruleset, devops, linux, docker

## Member repositories
- socfortress/Wazuh-Rules (main) score 55

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:04:33.902472+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T04:40:12.022163+00:00, confidence not recorded.
  - readme: https://github.com/socfortress/Wazuh-Rules (fetched 2026-08-28T04:04:33.902472+00:00, sha eab2e698be36)
  - homepage: https://www.socfortress.co (fetched 2026-08-29T11:56:11.429331+00:00, sha aa854cad0f61)
- Data as of 2026-08-30T08:39:29.467469+00:00.
