Submit a pull request. We review it. Vetted rules ship in signed content updates — no forum, no moderation queue, no extension system.
Aperlock/chronolith-detection-rulesWe want the practitioner community to contribute detection logic. We don't want to run a forum, and we don't want untrusted code running inside your clients' SIEMs.
RULE_SCHEMA.md. Map to MITRE ATT&CK where applicable. Include test cases in /tests/.We're not trying to be gatekeepers. We're trying to keep the quality bar high enough that MSPs can deploy every rule without tuning.
/tests/ that demonstrates the rule fires on the intended pattern and doesn't fire on the documented benign cases.The detection rules repository is open. Drop your email and you'll be in the first wave to hear about new contributor rules shipping in signed content updates.
Or watch the repo directly at github.com/Aperlock/chronolith-detection-rules