Chainsaw: search rules
chainsaw_search_rulesSearch detection rules by keyword, ATT&CK tag, level, status, or logsource to explain detections, assess technique coverage, or scope focused hunts.
Instructions
Find detection rules by keyword, ATT&CK tag, level, status or logsource.
Use it to explain a detection name from a hunt, to check coverage for a technique, or to pick a sub-tree for a focused hunt. Returns rule URIs readable as resources.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| tag | No | Substring of an ATT&CK tag, e.g. t1003 or credential | |
| kinds | No | Restrict to rule kinds: chainsaw, sigma, custom. Default all. | |
| level | No | critical, high, medium, low or info. | |
| limit | No | Rules per page. | |
| query | No | Words matched against title, description, tags, path, id. | |
| offset | No | Page start. | |
| status | No | stable, experimental, test or deprecated. | |
| logsource | No | Substring of Sigma logsource values, e.g. process_creation. | |
| path_prefix | No | Rule path prefix, e.g. rules/windows/powershell or evtx/persistence |