Detection packs for Rustinel.
Curated Sigma and YARA detections for Windows, Linux, and macOS.
Download packs | Documentation | Rustinel engine | Website
Install Rustinel, then choose a pack for your platform:
rustinel rules list
sudo rustinel rules install linux-essential
sudo rustinel service restartReplace linux-essential with a pack ID for your platform.
On Windows, use windows-essential and run the commands in an elevated PowerShell without sudo.
rustinel setup installs the Essential pack for you.
See Manage rule packs for updates and manual installation.
| Level | Use | Platforms |
|---|---|---|
| Essential | High-confidence detections with low expected noise. Start here. | Windows, Linux, macOS |
| Advanced | Broader coverage, with more environment-dependent false positives. | Windows, Linux, macOS |
| Hunting | Noisier leads for investigation. | Windows, Linux |
Packs are cumulative: Advanced includes Essential, and Hunting includes Advanced. Install one pack per endpoint. macOS packs are experimental. The tooling also supports typed IOC sets; current packs contain no IOC indicators.
Content is versioned independently from the engine. Each pack declares its minimum Rustinel version, and the updater checks compatibility before installing it. See pack manifests for membership and releases for changes.
Each detection lives once in rules/; packs reference it by its stable ID.
New detections should map to ATT&CK, use supported telemetry, and include a reproducible test where possible.
uv sync --frozen
uv run python tools/validate.py
uv run python tools/build_packs.py