Detection Wizard
Detection rules are scattered, duplicated, and unmanaged once scale is introduced. Sigma, YARA, Suricata, and Splunk rules exist across hundreds of repositories, often rewritten with small cosmetic changes and no shared structure. Detection Wizard was created primarily to gather rules, centralize them, and remove duplication across sources.
Once large scale collection became the goal, normalization became unavoidable. I enjoy defense in depth I will always like more rules rather than less and just remove what has a high false positive rate for your enviroment. Understand coverage, remove redundancy, and avoid importing the same detection idea multiple times under different names. Deduplication made it obvious how frequently identical logic is reused across ecosystems with only variable names or comments changed.
Automation quickly became mandatory. Repositories had to be cloned, parsed by content instead of extension, filtered by rule type, and processed in a deterministic order. Sequential execution was not a design preference. It was required to maintain correctness and operator trust. Parallel execution without strict state control caused inconsistent results and unpredictable behavior.
The project also reframed how I think about detections as a defensive supply chain. Public rules vary widely in quality, freshness, and intent. Some are well maintained and actionable. Others are outdated or misleading. Treating detections as code that must be curated, reviewed, deduplicated, and tracked became non negotiable once volume increased.
Check out some great links where I gather these rules from



