Detection-Wizard is designed to simplify rule management and enhance threat detection capabilities. This is a GUI tool that consolidates detection rules from multiple sources into a single central repository. Whether you're working with YARA, Suricata, Sigma, Sysmon, QRadar or Splunk. IOCs have also been added so you can manage your infastructure before and after and attack and see your security posture.
-
Multi-Tool Support:
-
117,000+ YARA files
-
270,000+ YARA rules
-
360+ Suricata files
-
9,700+ Sigma files
-
5 Sysmon Configurations files
-
SIEMS
- Splunk
- QRadar
- Sentinel
-
-
Cross-format rule conversion:
Check any of Sigma, Splunk, QRadar, or Sentinel as an output target and every selected tool's filtered rules are translated into that rule language where the translation can be done safely (plain field matches, and/or/not, 1-of/all-of, regex). Rules that use constructs outside that supported subset (aggregations, correlation rules, exotic modifiers) are left in their original format rather than risk emitting a wrong detection. Check more than one target (e.g. Splunk + Sentinel) and you get independent output folders for each.
Contributions are welcome! Whether you have suggestions for new sources, improvements in parsing logic, or additional features, please feel free to open an issue or submit a pull request. 💡
