Detection content for your stack.
Signed feeds, validated on a real engine, clearly licensed per pack, plug them into the SIEM, firewall, DNS or threat-intel platform you already run. Each pack is sold separately, one key.
This month: 70 new malware families forged from real-world samples.
Start with the essentials. Or take everything, at half price.
Prices shown per month for readability, billed annually. One key, whatever you pick.
Sigma + YARA
The two feeds that cover 90% of needs: behavior (SIEM) + files/malware.
- ›6,700+ Sigma (SPL/KQL/ECS/AQL) + 17,000+ YARA
- ›Every rule compile-validated, 0 FP on a benign corpus
- ›CACAO 2.0 playbooks, cross-engine linked, continuously updated
The whole catalogue
All 12 packs together, one key. Total coverage, at half the à-la-carte price.
- ✓Sigma, YARA, IOC, NIDS, Cloud-Native, Nuclei
- ✓WAF, SAST, Policy-as-code, osquery, Velociraptor, LLM Red-Team
- ✓A CACAO 2.0 playbook on every engine, cross-engine linked
- ✓New original families every month
- ✓One key, one sync script, every engine
Or build your coverage, pack by pack.
Per-month prices, billed annually. Every pack ships its CACAO 2.0 investigation playbook, cross-engine linked.
Detection that holds up in front of the auditor
Every subscription includes the per-requirement NIS2 and ReCyF coverage map, the OSCAL export and the connector that pre-fills your GRC. Detection and proof, in the same flow. Design coverage with gaps shown, not a certification: your CISO validates.
Ready-to-run SIEM detection: every rule validated on the real engine (zero-false-positive gate), delivered pre-converted for Splunk, Sentinel, Elastic, CrowdStrike and Panther, and mapped to NIS2/ReCyF.
File and malware detection, every rule compile-validated on the real engine, licenses vetted. For EDR, DFIR, mail gateway. Delivered mapped to NIS2/ReCyF.
Aggregated indicators of compromise (IPs, domains, URLs, hashes), ready to plug into your stack. Multi-format: CSV, STIX 2.1, MISP, blocklists, RPZ.
Network detection (IDS/IPS) for Suricata, every rule validated on the real engine, licenses filtered (ET OPEN and MIT sources). Delivered mapped to NIS2/ReCyF.
Runtime detection for containers/Kubernetes/Linux (Falco, validated on the real engine) plus cloud audit (K8s, AWS CloudTrail, Okta, GCP). Delivered mapped to NIS2/ReCyF.
Exposed-vulnerability detection, tested on the real engine, prioritized by what is actively exploited (CVE, CISA KEV, EPSS join). KEV Rapid-Response bundle included.
31,000+ defensive adversarial prompts (injection, jailbreak, PII leakage, toxicity, excessive agency, misinformation, DoS) to test your LLM applications. Mapped to OWASP LLM Top 10, EU AI Act (Annex IV), MITRE ATLAS, NIST. Replay with garak/promptfoo, on-prem. ~50% original content.
OPA/Rego policies validated on the real engine, mapped by framework (CIS, NIST, ISO 27001, NIS2, DORA…). Compliance coverage map and gaps exportable to OSCAL.
Web application firewall (OWASP CRS) tested on the real Coraza engine, with per-technology anti-false-positive tuning. Plus 700+ virtual-patches that name the exact CVE blocked.
Static code analysis validated on the real engine, licenses vetted per file, mapped to CWE/OWASP. Plus 1,371 secret patterns and in-house rules. Covers NIS2 secure development.
Endpoint hunting validated against the real osquery schema (every table exists), mapped to ATT&CK, multi-OS (Linux/macOS/Windows) and CIS benchmarks.
VQL artifacts for IR and threat hunting: forensic collection and malware hunting (YARA converted to VQL in-house), ATT&CK-mapped. Clear licenses. DFIR bundle with the YARA pack.
For reference: SOC Prime charges $249 per seat per month, Proofpoint ET Pro around $900 per sensor per year. Here the price is per team, with no seat or sensor limit.
Enterprise
For MSSPs that scale: multi-client usage, bespoke detection, SLA, and an OEM license if you embed the feed in your own service.
- ✓Multi-client usage: one license, your whole managed fleet
- ✓Negotiated OEM / redistribution license
- ✓Bespoke rules for your stack, every quarter
- ✓Early access to new families
- ✓Priority SLA + a fractional-CISO point of contact
- ✓Private feed / on-prem mirror
One license. Your whole client base protected.
The official semgrep-rules repo is no-resale. We built an alternative where every source license is vetted, shipped safely, not quietly. With multi-client usage, a single Complete subscription protects every client you manage.
Cloning a hundred repos isn’t the hard part. What comes next is.
On the real engine, not a linter
Every rule compiles on the engine you run and passes a zero-false-positive gate on a benign corpus. What does not compile, or lights up, never reaches the feed.
Our own research, every month
When a family moves in the wild, we analyse it and forge detection around the code it shares, not a hash that is stale by Thursday. Content you will not find in any public repo.
A playbook on every engine, cross-engine linked
Every detection, Sigma, YARA, network, cloud, WAF, osquery, Velociraptor, carries its CACAO 2.0 playbook, with a step that corroborates the threat via your other detections of the same ATT&CK technique, across all 8 engines. No one else links detection to response like this.
Your rules, mapped to NIS2 and ReCyF requirements
Every subscription ships with a per-requirement coverage map (NIS2, ReCyF) plus the list of gaps, a readable report and an OSCAL export, and a connector that pre-fills your GRC (CISO Assistant) through its API. This is design coverage with gaps shown honestly, not a certification nor automatic compliance: your CISO validates.
Try the demo pack. Free.
Download a real pack, check it compiles in your SIEM, judge the coverage. Then take what you need, a pack, the core bundle, or everything at half price.