Find tools that fit your workflow.

Start with a rule format, exchange standard or integration. Each collection shows what a tool is documented to do, with a direct path to the source.

Read the support mode

Storing a YARA rule is different from running it. Importing STIX is different from serving TAXII. A connector may require a separate component or licence. The notes explain these differences.

Evidence, not a compatibility test

These are dated documentation checks. We have not tested each integration end to end. An absent tag means this research pass has not established support; it does not mean a tool lacks it. How tags are assigned.

Rules & exchange standards

Sigma6 tools

Documented work with Sigma detection rules. The profile explains whether a tool writes, imports, converts or applies rules.

YARA13 tools

Documented work with YARA rules or matching. Check the profile for scanning, rule handling and component requirements.

STIX6 tools

Documented STIX data handling. Import, export and supported versions vary by tool.

TAXII3 tools

Documented TAXII exchange. Client, server and protocol-version support are recorded separately in each profile.

Specific integrations

MISP14 tools

A documented integration with MISP. Check direction, connector requirements and the linked upstream instructions.

TheHive3 tools

A documented integration with TheHive. The evidence describes the actual exchange or action.

Cortex2 tools

A documented integration with Cortex analyzers or responders, with component requirements in the source.

OpenCTI2 tools

A documented integration with OpenCTI. Connector availability does not establish every deployment or edition is supported.

Suricata4 tools

Documented exchange with Suricata, such as rule output or event ingestion. Read the profile for the precise scope.

Elastic4 tools

Documented work with an Elastic component. Elasticsearch storage, rule conversion and event forwarding are different functions.

Splunk4 tools

A documented Splunk integration or output. Check any app, connector or conversion requirement before deployment.

Combine a capability, an integration and other criteria in the main index.

Explore all tools