As we continue to develop Rulezet, we are looking to expand the platform’s capabilities by supporting additional threat intelligence and detection rule formats. Our goal is to provide a comprehensive, centralized hub for managing and converting security rules efficiently.
To ensure we prioritize the right additions, we want to hear from you. Which of the following formats would be the most valuable for your workflow?
-
ATR (Attacker Technique Research)
-
CRS (OWASP Core Rule Set)
-
NOVA
-
NSE (Nmap Scripting Engine)
-
SIGMA
-
SURICATA
-
WAZUH
-
YARA
-
ZEEK
Maintaining Integrity Through Validation
When integrating new formats into Rulezet, our primary concern is maintaining the reliability and integrity of the rules stored within the system.
It is absolutely essential that any new format we support includes a robust mechanism for syntactic and logical validation. Before a rule is accepted or converted, Rulezet must be able to verify that it is structurally sound and functional. This requires a reliable method—such as a dedicated compiler, linter, or schema validator—to programmatically confirm that a rule is valid.
By enforcing these validation checks, we guarantee that the rules managed in Rulezet are ready for deployment and will perform as expected in your security environment, preventing errors that could lead to gaps in detection or system instability.
We would love to get your input: Which of these formats should be next on our roadmap, and are there specific validation tools or libraries you would recommend for those formats?