Network detection, ready for Suricata.

A permissively-licensed open Suricata ruleset, but only the resalable BSD range, license-filtered, and validated on the real Suricata engine before delivery. Load it, it runs.

63 000+
rules
Open-source
BSD range
Suricata
real-engine validated
Ed25519
signed, updated

What we added recently

A living feed: here is the coverage added to it, dated.

  • +67 règles
  • +158 règles
  • +320 règles
  • +133 règles
  • +19 règles
  • +271 règles

Threats on the wire.

Malware & C2

Command-and-control traffic, malware families, exfiltration.

Exploits & CVEs

Exploitation attempts against known vulnerabilities on the wire.

Scanners & recon

Port scans, recon tools, automated sweeping.

Phishing & web

Web attacks, phishing kits, malicious redirects.

Trojans & bots

Trojans, botnets, adware/PUP.

Policy & protocols

Protocol anomalies, policy, suspicious traffic.

A permissively-licensed open Suricata ruleset (resalable BSD range; the GPLv2 range is excluded by the license filter) aggregated with complementary MIT sources, re-SIDed to avoid collisions. Copyrights and licenses retained in the pack.

License-filtered, engine-validated.

01
Multi-source, license-filtered

An open ruleset (BSD range) aggregated with MIT sources, only the resalable is shipped, GPLv2 excluded automatically (license filter).

02
Validated on real Suricata

Every delivery passes `suricata -T` on the engine, 0 rules that fail to load.

03
Ready to load

Rules + classification.config + a suricata.yaml example, plug it in.

04
Ed25519-signed

The feed is signed; you verify its integrity before loading.

05
MSSP-redistributable

BSD allows redistribution to your clients, with attribution.

06
One key, kept current

A single subscription, updated as campaigns emerge.

Which Suricata version?

The rules target Suricata 7.x and are validated on the latest official image. Load `rules/et-open-bsd.rules` via `rule-files` in your suricata.yaml (an example is provided).

What license, and can I resell / MSSP?

Only the BSD range of a permissively-licensed open Suricata ruleset, BSD permits commercial redistribution with copyright retained. The GPLv2 range is excluded automatically. The BSD text and upstream copyrights ship in the pack.

How is it different from ET Pro?

ET Pro (Proofpoint) is a separate per-sensor commercial feed. Here we package the BSD range of a permissively-licensed open Suricata ruleset, license-filtered, engine-validated, signed, under one flat-rate key, MSSP-redistributable.

Ready to watch your network?

Annual subscription. Instant key. Cancel anytime.

€349 / month, billed annually €4,188 excl. tax
Try before you buy: free demo pack

A sample of our in-house rules across every engine we run (Sigma, YARA, osquery, Velociraptor, Falco, network, policy), each detection with its investigation playbook in the CACAO 2.0 standard, importable into your SOAR. The Sigma rules come already converted for 6 SIEMs: Splunk, Sentinel, Elastic, QRadar, CrowdStrike and Panther. A NIS2 compliance-coverage sample is included. Generated without AI.

Download the demo pack .zip

What this pack does not cover

What we do not cover, we tell you

No one detects 100%, and a feed that claims otherwise burns out your analyst. Anything that does not compile on the real engine, or lights up on a benign corpus, never reaches the pack. What a rule cannot see, we show as a gap rather than paper over it. And by default the agent observes and proposes, acting only after human validation (human-in-the-loop). You buy signal, not volume.

Detection that holds up in front of the auditor

The question is no longer only “can I detect?” but “can I prove it?”. Every subscription ships with the compliance layer, at no extra cost.

Design coverage, not a certification nor a real-time measurement: it evidences that the catalogue addresses the requirement, your CISO validates compliance.

Detection guides

The method behind the pack, on our blog.