wazuh_rules_info
Search and list Wazuh detection rules with filters for rule severity, compliance frameworks (PCI DSS, GDPR, HIPAA, NIST 800-53), and MITRE ATT&CK techniques to assess and refine detection coverage.
Instructions
Search and list Wazuh detection rules. Filter by rule level, compliance framework (PCI DSS, GDPR, HIPAA, NIST 800-53), or MITRE ATT&CK technique. Essential for understanding your detection coverage and tuning rules.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| search | No | Search rules by name, description, or ID | |
| level | No | Filter by rule level (0-15). Higher = more severe. | |
| pci | No | Filter by PCI DSS requirement (e.g., '10.2.5') | |
| gdpr | No | Filter by GDPR article (e.g., 'Art._32') | |
| hipaa | No | Filter by HIPAA control (e.g., '164.312.b') | |
| nist_800_53 | No | Filter by NIST 800-53 control (e.g., 'AU-12') | |
| mitre_technique | No | Filter by MITRE ATT&CK technique ID (e.g., 'T1059') | |
| limit | No | Maximum rules to return (1-500) | |
| offset | No | Pagination offset |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |