ThreatClaw · Free demo

Detection rules & investigation playbooks

A sample of ThreatClaw detection content — rules we author in-house, each paired with an investigation playbook an analyst follows when the rule fires. Sigma rules come already converted for Splunk, Microsoft Sentinel, Elastic, QRadar, CrowdStrike and Panther. Playbooks are in the CACAO 2.0 standard (OASIS), importable into your SOAR, and generated without AI — every step derives from a fact the rule carries, nothing is invented.

Full catalog: 6,400+ Sigma and 12,000+ YARA rules across 8 engines, each with a playbook. → https://threatclaw.io/feeds

Sigma rules In-house

8 behavioral detection rules, each with SIEM conversions and an investigation playbook.
RuleATT&CKSIEM formatsPlaybook
AlwaysInstallElevated Installer Policy EnabledT1548.002SplunkSentinelElasticQRadarCrowdStrikePantheropen ›
Azure and AWS CLI Cloud Environment Recon from Windows EndpointT1526SplunkSentinelElasticQRadarCrowdStrikePantheropen ›
Browser Credential Database Staged in Temp or ArchiveT1005SplunkSentinelElasticQRadarCrowdStrikePantheropen ›
Known Vulnerable (BYOVD) Driver Loaded By HashT1068SplunkElasticQRadarPantheropen ›
Network Monitor nmcap Traffic CaptureT1040SplunkSentinelElasticQRadarCrowdStrikePantheropen ›
Pcalua/Forfiles Indirect Command ExecutionT1202SplunkSentinelElasticQRadarCrowdStrikePantheropen ›
Screensaver Hijack via SCRNSAVE.EXE to Suspicious PathT1546.002SplunkSentinelElasticQRadarCrowdStrikePantheropen ›
Windows Defender Disabled or Tamper Protection Turned OffT1562.001SplunkSentinelElasticQRadarCrowdStrikePantheropen ›

YARA rules In-house

13 file/memory signatures we forge ourselves, each with a file-triage playbook.
RuleFamilyATT&CKPlaybook
TC_C2_Sliver_Implant_GoSliverT1071, T1573, T1105open ›
TC_HackTool_Chisel_GoChiselT1090, T1572open ›
TC_HackTool_Impacket_OffensiveScriptImpacketT1003.006, T1021.002, T1047, T1557.001open ›
TC_HackTool_ligolo_ng_Goligolo-ngT1090, T1572open ›
Win32_mimidrvMimikatzT1003.001, T1003.002open ›
Win32_mimikatzMimikatzT1003.001, T1003.002open ›
Win32_mimilibMimikatzT1003.001, T1003.002open ›
Win32_mimiloveMimikatzT1003.001, T1003.002open ›
Win32_mimispoolMimikatzT1003.001, T1003.002open ›
x64_mimidrvMimikatzT1003.001, T1003.002open ›
x64_mimikatzMimikatzT1003.001, T1003.002open ›
x64_mimilibMimikatzT1003.001, T1003.002open ›
x64_mimispoolMimikatzT1003.001, T1003.002open ›

osquery In-house

2 rules, Endpoint hunting queries (SQL), each with a triage playbook. Browse the rules ›
RuleATT&CKPlaybook
Byovd edr killer vulnerable driver written to temporary pathT1562, T1562.001open ›
Dcsync credential replication via mimikatzT1003, T1003.006open ›

Velociraptor In-house

2 rules, DFIR collection artifacts, each with a triage playbook. Browse the rules ›
RuleATT&CKPlaybook
ThreatClaw.Yara.TC_MalDriver_0x3040_blacklotus_beta_driver_a42249a0T1068open ›
ThreatClaw.Yara.TC_MalDriver_prokiller64_10f36793T1068open ›

Cloud-Native (Falco) In-house

14 rules, Container / Kubernetes runtime rules, each with an investigation playbook. Browse the rules ›
RuleATT&CKPlaybook
TC Container Admin Command in ContainerT1609open ›
TC Container Escape Tool ExecutedT1611open ›
TC Cryptominer Executed in ContainerT1496open ›
TC Filesystem Mount in ContainerT1611open ›
TC Interactive Shell Spawned in ContainerT1059.004open ›
TC Kernel Module Operation in ContainerT1547.006open ›
TC Netcat Listener or Reverse Shell in ContainerT1059open ›
TC Network Recon Tool in ContainerT1046open ›
TC Package Manager Run in ContainerT1195open ›
TC Sensitive File Read in ContainerT1552.001open ›
TC Setuid Bit Set via chmod in ContainerT1548.001open ›
TC Shell Startup File Modified in ContainerT1546.004open ›
TC Write below Container Root Binary DirsT1543open ›
TC Write to Persistence Path in ContainerT1543open ›

NIDS In-house

6 rules, Network detection rules (Suricata / Snort syntax), each with a playbook. Browse the rules ›
RuleATT&CKPlaybook
ThreatClaw - domaine imitant microsoft (TLS SNI)open ›
ThreatClaw - domaine imitant microsoft (requete DNS)open ›
ThreatClaw - domaine imitant amazon (TLS SNI)open ›
ThreatClaw - domaine imitant amazon (requete DNS)open ›
ThreatClaw - domaine imitant bnpparibas (TLS SNI)open ›
ThreatClaw - domaine imitant bnpparibas (requete DNS)open ›

Policy (OPA / Rego) In-house

2 rules, Configuration & IaC compliance policies, each with a remediation playbook. Browse the rules ›
RuleATT&CKPlaybook
Les données doivent être stockées et traitées dans l'Union européenneopen ›
Authentification multifacteur obligatoire sur les comptes à privilègesopen ›

WAF & SAST In-house

Samples of two more engines in the catalog. These are not playbook objects (a virtual patch blocks, a SAST rule flags code), so they ship as rules only.
EngineFile
WAF virtual patchesvirtual-patch-sample.conf
SAST rulestc-js-express-cmdi.yaml
tc-py-django-cmdi.yaml

Compliance Ships with every subscription

The layer that answers "can I prove it to an auditor?" — design-coverage, not a certification. Identifiers only, no copyrighted normative text. Your CISO validates the actual compliance.
FileWhat it is
nis2-report.htmlNIS2 coverage report (open in a browser)
nis2-coverage.jsonPer-requirement design-coverage map, machine-readable
oscal-component-definition.jsonThe same mapping in OSCAL (NIST standard)