ThreatClaw · Free demo
Detection rules & investigation playbooks A sample of ThreatClaw detection content — rules we author in-house , each paired with an investigation playbook an analyst follows when the rule fires. Sigma rules come already converted for Splunk, Microsoft Sentinel, Elastic, QRadar, CrowdStrike and Panther. Playbooks are in the CACAO 2.0 standard (OASIS), importable into your SOAR, and generated without AI — every step derives from a fact the rule carries, nothing is invented.
Full catalog: 6,400+ Sigma and 12,000+ YARA rules across 8 engines, each with a playbook. → https://threatclaw.io/feeds
Sigma rules In-house 8 behavioral detection rules, each with SIEM conversions and an investigation playbook.
YARA rules In-house 13 file/memory signatures we forge ourselves, each with a file-triage playbook.
Rule Family ATT&CK Playbook TC_C2_Sliver_Implant_Go Sliver T1071, T1573, T1105 open › TC_HackTool_Chisel_Go Chisel T1090, T1572 open › TC_HackTool_Impacket_OffensiveScript Impacket T1003.006, T1021.002, T1047, T1557.001 open › TC_HackTool_ligolo_ng_Go ligolo-ng T1090, T1572 open › Win32_mimidrv Mimikatz T1003.001, T1003.002 open › Win32_mimikatz Mimikatz T1003.001, T1003.002 open › Win32_mimilib Mimikatz T1003.001, T1003.002 open › Win32_mimilove Mimikatz T1003.001, T1003.002 open › Win32_mimispool Mimikatz T1003.001, T1003.002 open › x64_mimidrv Mimikatz T1003.001, T1003.002 open › x64_mimikatz Mimikatz T1003.001, T1003.002 open › x64_mimilib Mimikatz T1003.001, T1003.002 open › x64_mimispool Mimikatz T1003.001, T1003.002 open ›
osquery In-house Rule ATT&CK Playbook Byovd edr killer vulnerable driver written to temporary path T1562, T1562.001 open › Dcsync credential replication via mimikatz T1003, T1003.006 open ›
Velociraptor In-house Rule ATT&CK Playbook ThreatClaw.Yara.TC_MalDriver_0x3040_blacklotus_beta_driver_a42249a0 T1068 open › ThreatClaw.Yara.TC_MalDriver_prokiller64_10f36793 T1068 open ›
Cloud-Native (Falco) In-house 14 rules, Container / Kubernetes runtime rules, each with an investigation playbook.
Browse the rules › Rule ATT&CK Playbook TC Container Admin Command in Container T1609 open › TC Container Escape Tool Executed T1611 open › TC Cryptominer Executed in Container T1496 open › TC Filesystem Mount in Container T1611 open › TC Interactive Shell Spawned in Container T1059.004 open › TC Kernel Module Operation in Container T1547.006 open › TC Netcat Listener or Reverse Shell in Container T1059 open › TC Network Recon Tool in Container T1046 open › TC Package Manager Run in Container T1195 open › TC Sensitive File Read in Container T1552.001 open › TC Setuid Bit Set via chmod in Container T1548.001 open › TC Shell Startup File Modified in Container T1546.004 open › TC Write below Container Root Binary Dirs T1543 open › TC Write to Persistence Path in Container T1543 open ›
NIDS In-house 6 rules, Network detection rules (Suricata / Snort syntax), each with a playbook.
Browse the rules › Rule ATT&CK Playbook ThreatClaw - domaine imitant microsoft (TLS SNI) — open › ThreatClaw - domaine imitant microsoft (requete DNS) — open › ThreatClaw - domaine imitant amazon (TLS SNI) — open › ThreatClaw - domaine imitant amazon (requete DNS) — open › ThreatClaw - domaine imitant bnpparibas (TLS SNI) — open › ThreatClaw - domaine imitant bnpparibas (requete DNS) — open ›
Policy (OPA / Rego) In-house 2 rules, Configuration & IaC compliance policies, each with a remediation playbook.
Browse the rules › Rule ATT&CK Playbook Les données doivent être stockées et traitées dans l'Union européenne — open › Authentification multifacteur obligatoire sur les comptes à privilèges — open ›
WAF & SAST In-house Samples of two more engines in the catalog. These are not playbook objects (a virtual patch blocks, a SAST rule flags code), so they ship as rules only.
Compliance Ships with every subscription The layer that answers "can I prove it to an auditor?" — design-coverage, not a certification. Identifiers only, no copyrighted normative text. Your CISO validates the actual compliance.
Generated by ThreatClaw — deterministic, no AI. Playbooks build on MITRE ATT&CK® and MITRE D3FEND™ © The MITRE Corporation. © CyberConsulting.fr — ThreatClaw. Full catalog: https://threatclaw.io/feeds