Skip to main content

Command Palette

Search for a command to run...

16. Wazuh Rule Collection

Updated
2 min read

Summary of Custom Wazuh Rulesets on GitHub

Below is a personal collection of custom Wazuh rulesets gathered from various community and organizational sources. These rules can be used for reference, customization, or direct application in your own setup. Using this ruleset will provide you with additional rules to use, reducing the time needed to rewrite them and the time spent parsing logs.

  • SOCFortress/Wazuh-Rules: Advanced Wazuh Rules for more accurate threat detection. Feel free to implement within your own Wazuh environment, contribute, or fork!

  • TristanGNS/wazuh-cjis-rules: Modular CJIS Compliance Ruleset for Wazuh. A maintainable, version-controlled collection of custom Wazuh rules mapped to CJIS Security Policy controls. Designed for easy auditing, deployment, and integration with SIEM workflows.

  • sametsazak/sysmon: Sysmon and wazuh integration with Sigma sysmon rules [updated]

  • MikhailKasimov/maltrail-wazuh-decoder-and-rules: Maltrail decoder and rules for Wazuh

  • TheMuntu/Wazuh-Detection: This is a collection of various Wazuh detection rules for vulnerabilities, malware and adversary emulations.

We have also collected and created some rules ourselves and shared them with the community at the link below. What sets us apart is that we filter out obsolete rules and keep them updated over time.

Comparison Table of Main Features

Project (GitHub)Monitoring ScopeProsConsHighlights
SOCFortress/Wazuh-RulesAdvanced detection: Sysmon, Office365, Defender, Sophos, MISP, Osquery, Yara, Suricata, Falco, ModSecurity, etc.Comprehensive, updated, auto-install scripts, SIGMA & Yara supportVery large, potential ID conflicts, may produce false positivesWindows/Linux support, MITRE mapping via SIGMA
TristanGNS/wazuh-cjis-rulesCompliance with FBI CJIS, mapping to CJIS/NIST 800-53Modular, clear mapping, audit-readySpecialized, limited to CJIS, some rules still in progressFocused on compliance, version-controlled
sametsazak/sysmonSIGMA-based rules for Sysmon (Windows)Extensive SIGMA rules, advanced Windows detectionWindows-only, may flood alerts, repo oldSIGMA integration, detailed Sysmon analysis
MikhailKasimov/maltrail-wazuh-decoder-and-rulesMaltrail log processingSpecialized, easy integration, updatedNarrow focus, requires ID adjustmentMaltrail integration, clear ID guidance
TheMuntu/Wazuh-DetectionVulnerability, malware, adversary emulationMultiple illustrative rules, updated 2024Few stars, mainly examples, limited integrationFocus on IOC & Blue Team exercises
sanesecurityguy/opnsense-…OPNsense firewall log decodingReady to use for OPNsenseOld version, limited updates-
314 views

More from this blog

F

FPT Metrodata Indonesia Cyber Security

643 posts

FPT Metrodata Indonesia (FMI) provides news, analysis & guides on cybersecurity and threat intelligence for Indonesia & Vietnam. Visit https://news.fmisec.com. FMI: https://fmisec.com