Detection content for your stack.

Signed feeds, validated on a real engine, clearly licensed per pack, plug them into the SIEM, firewall, DNS or threat-intel platform you already run. Each pack is sold separately, one key.

This month: 70 new malware families forged from real-world samples.

Real engine
every rule compiles, not a linter
0 FP
on a benign corpus of thousands of files
Playbook
on every engine, cross-engine linked
12 packs
one key · Ed25519-signed

Start with the essentials. Or take everything, at half price.

Prices shown per month for readability, billed annually. One key, whatever you pick.

Core bundle

Sigma + YARA

The two feeds that cover 90% of needs: behavior (SIEM) + files/malware.

€549/mo
€6,588 excl. tax / year · billed annually
€698 à la carte−€1,500
Subscribe · Sigma + YARA
  • 6,700+ Sigma (SPL/KQL/ECS/AQL) + 17,000+ YARA
  • Every rule compile-validated, 0 FP on a benign corpus
  • CACAO 2.0 playbooks, cross-engine linked, continuously updated
Best value · −50%Complete bundle

The whole catalogue

All 12 packs together, one key. Total coverage, at half the à-la-carte price.

€2,000/mo
€1,990 / month · billed annually, €23,880 excl. tax
€48,800 à la carteSave €24,800 · −50%
Subscribe · Complete
  • Sigma, YARA, IOC, NIDS, Cloud-Native, Nuclei
  • WAF, SAST, Policy-as-code, osquery, Velociraptor, LLM Red-Team
  • A CACAO 2.0 playbook on every engine, cross-engine linked
  • New original families every month
  • One key, one sync script, every engine

Or build your coverage, pack by pack.

Per-month prices, billed annually. Every pack ships its CACAO 2.0 investigation playbook, cross-engine linked.

Detection that holds up in front of the auditor

Every subscription includes the per-requirement NIS2 and ReCyF coverage map, the OSCAL export and the connector that pre-fills your GRC. Detection and proof, in the same flow. Design coverage with gaps shown, not a certification: your CISO validates.

7,000+ Sigma rules
15 % forged in-house

Ready-to-run SIEM detection: every rule validated on the real engine (zero-false-positive gate), delivered pre-converted for Splunk, Sentinel, Elastic, CrowdStrike and Panther, and mapped to NIS2/ReCyF.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
19,500+ YARA rules
38 % forged in-house

File and malware detection, every rule compile-validated on the real engine, licenses vetted. For EDR, DFIR, mail gateway. Delivered mapped to NIS2/ReCyF.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
3,589,000+ indicators

Aggregated indicators of compromise (IPs, domains, URLs, hashes), ready to plug into your stack. Multi-format: CSV, STIX 2.1, MISP, blocklists, RPZ.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
NIDS SuricataLearn more
63,182 rules

Network detection (IDS/IPS) for Suricata, every rule validated on the real engine, licenses filtered (ET OPEN and MIT sources). Delivered mapped to NIS2/ReCyF.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
Cloud-NativeLearn more
435 rules
3 % forged in-house

Runtime detection for containers/Kubernetes/Linux (Falco, validated on the real engine) plus cloud audit (K8s, AWS CloudTrail, Okta, GCP). Delivered mapped to NIS2/ReCyF.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
86,000+ templates

Exposed-vulnerability detection, tested on the real engine, prioritized by what is actively exploited (CVE, CISA KEV, EPSS join). KEV Rapid-Response bundle included.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
LLM Red-TeamLearn more
31,000+ prompts · 8 bundles
57 % forged in-house

31,000+ defensive adversarial prompts (injection, jailbreak, PII leakage, toxicity, excessive agency, misinformation, DoS) to test your LLM applications. Mapped to OWASP LLM Top 10, EU AI Act (Annex IV), MITRE ATLAS, NIST. Replay with garak/promptfoo, on-prem. ~50% original content.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
Policy-as-codeLearn more
2,590+ policies · 16 frameworks · 31 bundles

OPA/Rego policies validated on the real engine, mapped by framework (CIS, NIST, ISO 27001, NIS2, DORA…). Compliance coverage map and gaps exportable to OSCAL.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
1,200+ rules · incl. 700+ CVE virtual-patch
56 % forged in-house

Web application firewall (OWASP CRS) tested on the real Coraza engine, with per-technology anti-false-positive tuning. Plus 700+ virtual-patches that name the exact CVE blocked.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
960+ rules · 1,371 secrets · CWE/OWASP
7 % forged in-house

Static code analysis validated on the real engine, licenses vetted per file, mapped to CWE/OWASP. Plus 1,371 secret patterns and in-house rules. Covers NIS2 secure development.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
1,550+ queries · ATT&CK · Linux/macOS/Windows · CIS
18 % forged in-house

Endpoint hunting validated against the real osquery schema (every table exists), mapped to ATT&CK, multi-OS (Linux/macOS/Windows) and CIS benchmarks.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe
VelociraptorLearn more
460+ artifacts · in-house YARA→VQL · ATT&CK
46 % forged in-house

VQL artifacts for IR and threat hunting: forensic collection and malware hunting (YARA converted to VQL in-house), ATT&CK-mapped. Clear licenses. DFIR bundle with the YARA pack.

349 €/mo
billed annually, €4,188 excl. tax
Subscribe

For reference: SOC Prime charges $249 per seat per month, Proofpoint ET Pro around $900 per sensor per year. Here the price is per team, with no seat or sensor limit.

Enterprise · custom quote

Enterprise

For MSSPs that scale: multi-client usage, bespoke detection, SLA, and an OEM license if you embed the feed in your own service.

Custom quote
negotiated extended rights
Talk to an expert
  • Multi-client usage: one license, your whole managed fleet
  • Negotiated OEM / redistribution license
  • Bespoke rules for your stack, every quarter
  • Early access to new families
  • Priority SLA + a fractional-CISO point of contact
  • Private feed / on-prem mirror

One license. Your whole client base protected.

The official semgrep-rules repo is no-resale. We built an alternative where every source license is vetted, shipped safely, not quietly. With multi-client usage, a single Complete subscription protects every client you manage.

Complete€23,880 / yr
Deployed · 40 clients€600 / client
vs a fractional detection engineer≈ €30,000 / yr
Full coverage, from€50 / client / month

Cloning a hundred repos isn’t the hard part. What comes next is.

01 · Validated

On the real engine, not a linter

Every rule compiles on the engine you run and passes a zero-false-positive gate on a benign corpus. What does not compile, or lights up, never reaches the feed.

02 · Original

Our own research, every month

When a family moves in the wild, we analyse it and forge detection around the code it shares, not a hash that is stale by Thursday. Content you will not find in any public repo.

03 · Linked

A playbook on every engine, cross-engine linked

Every detection, Sigma, YARA, network, cloud, WAF, osquery, Velociraptor, carries its CACAO 2.0 playbook, with a step that corroborates the threat via your other detections of the same ATT&CK technique, across all 8 engines. No one else links detection to response like this.

04 · Compliance-mapped

Your rules, mapped to NIS2 and ReCyF requirements

Every subscription ships with a per-requirement coverage map (NIS2, ReCyF) plus the list of gaps, a readable report and an OSCAL export, and a connector that pre-fills your GRC (CISO Assistant) through its API. This is design coverage with gaps shown honestly, not a certification nor automatic compliance: your CISO validates.

Try the demo pack. Free.

Download a real pack, check it compiles in your SIEM, judge the coverage. Then take what you need, a pack, the core bundle, or everything at half price.