{
  "edgeTypes": {
    "consumes": {
      "color": "#3b63f3",
      "direction": "forward",
      "label": "uses Rulezet",
      "labelBackground": "#3b63f3",
      "labelColor": "#ffffff",
      "labelFont": "sans",
      "labelSize": 13,
      "width": 2
    },
    "uses": {
      "color": "#0f9d8a",
      "direction": "forward",
      "label": "uses",
      "labelBackground": "#0f9d8a",
      "labelColor": "#ffffff",
      "labelFont": "sans",
      "labelSize": 13,
      "width": 2
    }
  },
  "edges": [
    {
      "description": "A Rulezet instance pulls rules and bundles from another Rulezet instance through an admin-configured Connector. Each pull runs as a background connector_pull job that calls the remote sync API with an X-API-KEY header and imports rules and bundles with their tags, CVEs and ATT\u0026CK techniques. Items are matched by UUID only. Soft mode skips existing rules, hard mode updates them in place. Pull only: nothing is pushed back to the source.",
      "details": {
        "code": [
          "app/features/connector/connector_core.py",
          "app/api/connector/connector_sync_api.py"
        ],
        "endpoints": [
          "/api/sync/manifest",
          "/api/sync/stats",
          "/api/sync/rules",
          "/api/sync/bundles"
        ],
        "matching": "uuid",
        "modes": [
          "soft",
          "hard"
        ],
        "protocol": "REST (X-API-KEY)"
      },
      "from": "rulezet",
      "label": "federates with (Connector sync)",
      "to": "rulezet",
      "type": "uses"
    },
    {
      "description": "Rulezet uses Vulnerability-Lookup as its CVE reference. Every CVE shown on a rule or blog post links to its vulnerability.circl.lu page. A background job generates blog posts from CVE details and EPSS scores fetched from the Vulnerability-Lookup API, and a blog endpoint proxies CVE data from it to avoid browser CORS issues.",
      "details": {
        "code": [
          "app/features/jobs/job_handlers.py",
          "app/features/blog/blog.py",
          "app/static/js/vulnerability/"
        ],
        "endpoints": [
          "/api/cve/\u003cid\u003e",
          "/api/epss/\u003cid\u003e",
          "/vuln/\u003cid\u003e (links)"
        ],
        "protocol": "REST (public)"
      },
      "from": "rulezet",
      "label": "fetches CVE \u0026 EPSS data",
      "to": "vulnerability-lookup",
      "type": "uses"
    },
    {
      "description": "Admins register MISP servers in Rulezet (URL + API key, stored encrypted). A rule or bundle can be pushed as a MISP Object or a richer MISP Event (with tags and CVE attributes) through PyMISP, as a background misp_push job. Rules and bundles are also downloadable as MISP JSON, using the rulezet-metadata and rulezet-bundle object templates published in misp-objects.",
      "details": {
        "code": [
          "app/features/misp/misp_connector_core.py",
          "app/features/misp/rule/misp_object.py",
          "app/features/misp/bundle/misp_object.py"
        ],
        "job": "misp_push",
        "misp_objects": [
          "rulezet-metadata",
          "rulezet-bundle"
        ],
        "protocol": "REST via PyMISP (API key)"
      },
      "from": "rulezet",
      "label": "pushes rules as MISP events",
      "to": "misp",
      "type": "uses"
    },
    {
      "curve": "curved",
      "dashed": true,
      "description": "Rulezet embeds the MISP taxonomies and MISP galaxy repositories as git submodules and turns them into tags (TLP, PAP, threat actors, ...). An admin can refresh them with the update_misp_data background job, which runs git submodule update --remote.",
      "details": {
        "code": [
          "app/features/tags/tags_core.py",
          "app/features/jobs/job_handlers.py",
          "app/modules/"
        ],
        "job": "update_misp_data",
        "source": [
          "MISP/misp-taxonomies",
          "MISP/misp-galaxy"
        ]
      },
      "from": "rulezet",
      "label": "imports taxonomies \u0026 galaxies",
      "to": "misp",
      "type": "uses"
    },
    {
      "description": "To show and export a rule in STIX, Rulezet builds the rule's MISP event and sends it to the CTI-Transmute conversion API, which returns the STIX bundle. The endpoint can be pointed to a self-hosted CTI-Transmute with CTI_TRANSMUTE_URL.",
      "details": {
        "code": [
          "app/features/misp/misp_core.py",
          "app/features/rule/rule.py (/get_stix)"
        ],
        "config": "CTI_TRANSMUTE_URL",
        "endpoint": "https://cti-transmute.org/api/convert/misp_to_stix",
        "protocol": "REST"
      },
      "from": "rulezet",
      "label": "converts MISP to STIX",
      "to": "cti-transmute",
      "type": "uses"
    },
    {
      "description": "Admins register Velociraptor servers in Rulezet with their API client config (mutual TLS certificates, stored encrypted). Rulezet turns a rule into a Velociraptor artifact and registers it on the server over gRPC with a VQL artifact_set() call, as a background job.",
      "details": {
        "code": [
          "app/features/velociraptor/velociraptor_core.py",
          "app/features/rule/exporters/velociraptor_exporter.py"
        ],
        "protocol": "gRPC + mutual TLS (VQL)",
        "tested_with": "Velociraptor v0.77.1",
        "vql": "SELECT artifact_set(...) FROM scope()"
      },
      "from": "rulezet",
      "label": "pushes detection artifacts",
      "to": "velociraptor",
      "type": "uses"
    },
    {
      "description": "Rulezet embeds the Pivotick library to draw interactive graphs (e.g. on the rule detail page).",
      "details": {
        "code": "app/modules/pivotick"
      },
      "from": "rulezet",
      "label": "draws graphs with",
      "to": "pivotick",
      "type": "uses"
    },
    {
      "description": "Vulnerability-Lookup calls Rulezet's public API to list the detection rules that cover a vulnerability (CVE, GHSA, ...). It calls this endpoint heavily and depends on its exact JSON format. On Rulezet's side the response is cached for 60s and only returns active rules.",
      "details": {
        "cache": "60s",
        "code": [
          "app/api/rule/rule_public_api.py",
          "app/features/rule/rule_core.py"
        ],
        "endpoint": "GET /api/rule/public/search_rules_by_cve?cve_ids=...",
        "protocol": "REST (public, no auth)"
      },
      "from": "vulnerability-lookup",
      "label": "queries rules by CVE",
      "to": "rulezet",
      "type": "consumes"
    },
    {
      "description": "In AIL's tracker and retro hunt forms, an analyst can search Rulezet and paste a rulezet.org rule URL. AIL extracts the rule id, fetches the rule from Rulezet's public API and imports it as a YARA tracker (only YARA rules are accepted). Each AIL user can also store a Rulezet API key in their profile.",
      "details": {
        "code": [
          "ail-framework: var/www/blueprints/hunters.py",
          "ail-framework: bin/lib/ail_users.py"
        ],
        "endpoint": "GET /api/rule/public/detail/\u003cid\u003e",
        "formats": "yara",
        "protocol": "REST"
      },
      "from": "ail",
      "label": "imports YARA rules",
      "to": "rulezet",
      "type": "consumes"
    },
    {
      "description": "Flowintel has a Rulezet 'receive from' connector module: from a case, an analyst fetches a rule or bundle from a configured Rulezet instance and stores it on the case (title, format, content, version). Instances use an API key and optional SSL verification.",
      "details": {
        "code": [
          "flowintel: app/modules/receive_from/rulezet_rule.py",
          "flowintel: app/static/js/case/ModuleComponents/Rulezet.js"
        ],
        "config": "RULEZET_VERIFY_SSL",
        "endpoint": "GET /api/rule/public/detail/\u003cid\u003e",
        "protocol": "REST (X-API-KEY / Bearer)"
      },
      "from": "flowintel",
      "label": "attaches rules to cases",
      "to": "rulezet",
      "type": "consumes"
    },
    {
      "description": "MISP-Workbench has a 'Rulezet vuln check' hunt type: given a vulnerability id (e.g. CVE-2021-44228), it looks up the matching detection rules on rulezet.org.",
      "details": {
        "code": [
          "misp-workbench: api/app/services/rulezet.py",
          "misp-workbench: docs/features/hunts.md"
        ],
        "endpoint": "GET /api/rule/public/search_rules_by_cve?cve_ids=...",
        "hunt_type": "rulezet",
        "protocol": "REST (public)"
      },
      "from": "misp-workbench",
      "label": "hunts rules by CVE",
      "to": "rulezet",
      "type": "consumes"
    },
    {
      "description": "zsazsa's vulnerability advisory and detection engineering wizards have a 'Search Rulezet' button that finds existing rules by CVE or MITRE ATT\u0026CK technique, shown as 'Existing coverage (Rulezet)' in the product. zsazsa also calls Rulezet's validate endpoint to check a rule before a detection request can become Active. Its rule viewer reuses Rulezet's syntax highlighters.",
      "details": {
        "code": [
          "zsazsa: core/rulezet_lookup.py",
          "zsazsa: webapp/routes/api.py"
        ],
        "config": "RULEZET_URL",
        "endpoints": [
          "GET /api/rule/public/search_rules_by_cve",
          "GET /api/rule/public/search_rules_by_attack",
          "/api/rule/public/validate"
        ],
        "protocol": "REST (public)"
      },
      "from": "zsazsa",
      "label": "looks up \u0026 validates rules",
      "to": "rulezet",
      "type": "consumes"
    }
  ],
  "meta": {
    "description": "How Rulezet connects to the other projects of its ecosystem. Arrow = who calls or uses whom. Checked against the code of each project (September 2026).",
    "linkDistance": 330,
    "readOnly": true,
    "title": "Projects linked to Rulezet"
  },
  "nodeTypes": {
    "project": {
      "borderWidth": 0,
      "color": "transparent",
      "imageFit": "contain",
      "label": "Project",
      "labelBackground": "none",
      "labelFont": "sans",
      "labelSize": 17,
      "shape": "circle",
      "size": 44
    }
  },
  "nodes": [
    {
      "description": "Community platform for sharing, reviewing and managing detection rules (YARA, Sigma, Suricata, Zeek, ...).",
      "github": "rulezet/rulezet-core",
      "githubInfo": {
        "archived": false,
        "description": "Rulezet is an open-source web platform for sharing, evaluating, improving, and managing cybersecurity detection rules (YARA, Sigma, Suricata, etc). It aims to foster collaboration among professionals and enthusiasts to improve the quality and reliability of detection rules. ",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 9,
        "fullName": "rulezet/rulezet-core",
        "homepage": "https://rulezet.org/docs/",
        "issues": 14,
        "language": "Python",
        "license": "AGPL-3.0",
        "pushedAt": "2026-09-21T12:45:58Z",
        "stars": 55,
        "topics": [
          "cti",
          "network-detection",
          "network-security",
          "threat-intelligence",
          "yara"
        ],
        "url": "https://github.com/rulezet/rulezet-core"
      },
      "id": "rulezet",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/rulezet/logo.png",
      "imageFit": "contain",
      "label": "Rulezet",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/rulezet/"
        }
      ],
      "size": 64,
      "tags": [
        "cti",
        "network-detection",
        "network-security",
        "threat-intelligence",
        "yara"
      ],
      "type": "project",
      "url": "https://rulezet.org"
    },
    {
      "description": "Open source threat intelligence sharing platform.",
      "github": "MISP/MISP",
      "githubInfo": {
        "archived": false,
        "description": "MISP (core software) - Open Source Threat Intelligence and Sharing Platform",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 1637,
        "fullName": "MISP/MISP",
        "homepage": "https://www.misp-project.org/",
        "issues": 2923,
        "language": "PHP",
        "license": "AGPL-3.0",
        "pushedAt": "2026-09-23T09:16:13Z",
        "stars": 6547,
        "topics": [
          "cti",
          "cybersecurity",
          "fraud-detection",
          "fraud-management",
          "fraud-prevention",
          "information-exchange",
          "information-security",
          "information-sharing",
          "intelligence",
          "malware-analysis",
          "misp",
          "security",
          "stix",
          "threat-analysis",
          "threat-hunting",
          "threat-intel",
          "threat-intelligence",
          "threat-intelligence-platform",
          "threat-sharing",
          "threatintel"
        ],
        "url": "https://github.com/MISP/MISP"
      },
      "id": "misp",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/misp/logo.png",
      "imageFit": "contain",
      "label": "MISP",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/misp/"
        }
      ],
      "tags": [
        "cti",
        "cybersecurity",
        "fraud-detection",
        "fraud-management",
        "fraud-prevention",
        "information-exchange",
        "information-security",
        "information-sharing",
        "intelligence",
        "malware-analysis",
        "misp",
        "security",
        "stix",
        "threat-analysis",
        "threat-hunting",
        "threat-intel",
        "threat-intelligence",
        "threat-intelligence-platform",
        "threat-sharing",
        "threatintel"
      ],
      "type": "project",
      "url": "https://www.misp-project.org"
    },
    {
      "description": "Fast vulnerability (CVE, GHSA, ...) lookup and correlation service.",
      "github": "vulnerability-lookup/vulnerability-lookup",
      "githubInfo": {
        "archived": false,
        "description": "Vulnerability-Lookup facilitates quick correlation of vulnerabilities from various sources, independent of vulnerability IDs, and streamlines the management of Coordinated Vulnerability Disclosure (CVD). ",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 92,
        "fullName": "vulnerability-lookup/vulnerability-lookup",
        "homepage": "https://www.vulnerability-lookup.org",
        "issues": 70,
        "language": "Python",
        "license": "AGPL-3.0",
        "pushedAt": "2026-09-23T12:05:44Z",
        "stars": 576,
        "topics": [
          "cvd",
          "cvd-policy",
          "cve",
          "vulnerability-databases",
          "vulnerability-lookup"
        ],
        "url": "https://github.com/vulnerability-lookup/vulnerability-lookup"
      },
      "id": "vulnerability-lookup",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/vulnerability-lookup/logo.png",
      "imageFit": "contain",
      "label": "Vulnerability-Lookup",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/vulnerability-lookup/"
        }
      ],
      "tags": [
        "cvd",
        "cvd-policy",
        "cve",
        "vulnerability-databases",
        "vulnerability-lookup"
      ],
      "type": "project",
      "url": "https://vulnerability.circl.lu"
    },
    {
      "description": "CTI format conversion service (MISP \u003c-\u003e STIX).",
      "github": "MISP/cti-transmute",
      "githubInfo": {
        "archived": false,
        "description": "An online service for converting cyber threat intelligence format, built to promote interoperability and seamless data exchange",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 5,
        "fullName": "MISP/cti-transmute",
        "homepage": "https://cti-transmute.org",
        "issues": 1,
        "language": "JavaScript",
        "license": "AGPL-3.0",
        "pushedAt": "2026-09-08T21:25:24Z",
        "stars": 39,
        "topics": [
          "cti",
          "cyberthreatintelligence",
          "misp",
          "stix",
          "stix2",
          "threat-intelligence",
          "threat-intelligence-data"
        ],
        "url": "https://github.com/MISP/cti-transmute"
      },
      "id": "cti-transmute",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/cti-transmute/logo.png",
      "imageFit": "contain",
      "label": "CTI-Transmute",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/cti-transmute/"
        }
      ],
      "tags": [
        "cti",
        "cyberthreatintelligence",
        "misp",
        "stix",
        "stix2",
        "threat-intelligence",
        "threat-intelligence-data"
      ],
      "type": "project",
      "url": "https://cti-transmute.org"
    },
    {
      "description": "Endpoint visibility, DFIR and hunting tool driven by VQL artifacts.",
      "github": "Velocidex/velociraptor",
      "githubInfo": {
        "archived": false,
        "description": "Digging Deeper....",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 657,
        "fullName": "Velocidex/velociraptor",
        "homepage": "https://docs.velociraptor.app/",
        "issues": 75,
        "language": "Go",
        "license": "",
        "pushedAt": "2026-09-21T09:03:37Z",
        "stars": 4268,
        "topics": [
          "digital-forensics",
          "endpoint-discovery",
          "endpoint-protection",
          "endpoint-security",
          "forensics-investigations",
          "incident-response",
          "inventory-management"
        ],
        "url": "https://github.com/Velocidex/velociraptor"
      },
      "id": "velociraptor",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/velociraptor/logo.png",
      "imageFit": "contain",
      "label": "Velociraptor",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/velociraptor/"
        }
      ],
      "tags": [
        "digital-forensics",
        "endpoint-discovery",
        "endpoint-protection",
        "endpoint-security",
        "forensics-investigations",
        "incident-response",
        "inventory-management"
      ],
      "type": "project",
      "url": "https://docs.velociraptor.app"
    },
    {
      "description": "Analysis of Information Leaks framework: collects and analyses unstructured data, with YARA trackers and retro hunts.",
      "github": "ail-project/ail-framework",
      "githubInfo": {
        "archived": false,
        "description": "AIL framework - Analysis Information Leak framework",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 145,
        "fullName": "ail-project/ail-framework",
        "homepage": "",
        "issues": 136,
        "language": "Python",
        "license": "AGPL-3.0",
        "pushedAt": "2026-09-22T15:19:25Z",
        "stars": 1018,
        "topics": [
          "ail-framework",
          "darkweb",
          "darkweb-scraping",
          "data-mining",
          "information-extraction",
          "information-security",
          "leak"
        ],
        "url": "https://github.com/ail-project/ail-framework"
      },
      "id": "ail",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/ail/logo.png",
      "imageFit": "contain",
      "label": "AIL",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/ail/"
        }
      ],
      "tags": [
        "ail-framework",
        "darkweb",
        "darkweb-scraping",
        "data-mining",
        "information-extraction",
        "information-security",
        "leak"
      ],
      "type": "project",
      "url": "https://www.ail-project.org"
    },
    {
      "description": "Case management and analyst workflow platform.",
      "github": "flowintel/flowintel",
      "githubInfo": {
        "archived": false,
        "description": "An open source platform to support analysts to organise their case and tasks",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 26,
        "fullName": "flowintel/flowintel",
        "homepage": "https://flowintel.github.io/flowintel-doc ",
        "issues": 17,
        "language": "Python",
        "license": "AGPL-3.0",
        "pushedAt": "2026-09-23T12:23:49Z",
        "stars": 158,
        "topics": [
          "case-management",
          "flowintel",
          "incident-response",
          "threatintel"
        ],
        "url": "https://github.com/flowintel/flowintel"
      },
      "id": "flowintel",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/flowintel/logo.png",
      "imageFit": "contain",
      "label": "Flowintel",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/flowintel/"
        }
      ],
      "tags": [
        "case-management",
        "flowintel",
        "incident-response",
        "threatintel"
      ],
      "type": "project"
    },
    {
      "description": "Analyst workbench around MISP data, with hunts over external sources.",
      "github": "MISP/misp-workbench",
      "githubInfo": {
        "archived": false,
        "description": "Built for the frontlines of cyber defense, our next-generation MISP empowers edge deployments and threat hunters with fast, lightweight, and actionable intelligence, anytime, anywhere.",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 6,
        "fullName": "MISP/misp-workbench",
        "homepage": "https://misp-workbench.readthedocs.io/en/latest/",
        "issues": 8,
        "language": "Python",
        "license": "AGPL-3.0",
        "pushedAt": "2026-09-23T12:29:19Z",
        "stars": 31,
        "topics": [
          "misp",
          "threat-hunting",
          "threat-intelligence"
        ],
        "url": "https://github.com/MISP/misp-workbench"
      },
      "id": "misp-workbench",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/misp-workbench/logo.png",
      "imageFit": "contain",
      "label": "MISP-Workbench",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/misp-workbench/"
        }
      ],
      "tags": [
        "misp",
        "threat-hunting",
        "threat-intelligence"
      ],
      "type": "project"
    },
    {
      "description": "CTI program management and production platform built around MISP.",
      "github": "zsazsa-project/zsazsa",
      "githubInfo": {
        "archived": false,
        "description": "A CTI program management and production platform built around MISP",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 8,
        "fullName": "zsazsa-project/zsazsa",
        "homepage": "",
        "issues": 9,
        "language": "Python",
        "license": "AGPL-3.0",
        "pushedAt": "2026-09-23T07:50:34Z",
        "stars": 40,
        "topics": [
          "cti",
          "misp"
        ],
        "url": "https://github.com/zsazsa-project/zsazsa"
      },
      "id": "zsazsa",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/zsazsa/logo.png",
      "imageFit": "contain",
      "label": "zsazsa",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/zsazsa/"
        }
      ],
      "tags": [
        "cti",
        "misp"
      ],
      "type": "project"
    },
    {
      "description": "Graph visualization library.",
      "github": "Pivotick/Pivotick",
      "githubInfo": {
        "archived": false,
        "description": "Pivotick is network graph library to facilitate pivoting.",
        "fetchedAt": "2026-09-23T12:33:10.436Z",
        "forks": 6,
        "fullName": "Pivotick/Pivotick",
        "homepage": "https://pivotick.github.io/Pivotick/",
        "issues": 1,
        "language": "TypeScript",
        "license": "",
        "pushedAt": "2026-09-17T09:02:06Z",
        "stars": 30,
        "topics": [
          "infovis",
          "network-vis",
          "network-visualization"
        ],
        "url": "https://github.com/Pivotick/Pivotick"
      },
      "id": "pivotick",
      "image": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/pivotick/logo.png",
      "imageFit": "contain",
      "label": "Pivotick",
      "links": [
        {
          "label": "Site page",
          "url": "https://ecrou-exact.github.io/project-graph/hugo-example/projects/pivotick/"
        }
      ],
      "tags": [
        "infovis",
        "network-vis",
        "network-visualization"
      ],
      "type": "project",
      "url": "https://pivotick.github.io/Pivotick/"
    }
  ],
  "version": 1
}