
VEDAS-Driven Autonomous Generation + Community Contributions of Suricata & Nuclei Rules for over 12000 CVEs
This repository is an open, collaborative validation space for CVE detection content:
Most signatures are generated autonomously by ARPSyndicate's Vulnerability & Exploit Data Aggregation System (VEDAS). AI lets us create detection content quickly and at scale from vulnerability and exploit intelligence. Reliable detection still needs transparency, human review and real-world testing, so the content is published here for the community to review, validate, fix and extend through issues and pull requests.
12,466 unique CVEs covered — each with a Suricata rule and a Nuclei template.
| CVE year | Suricata Signatures | Nuclei Signatures |
|---|---|---|
| 1999 | 4 | 4 |
| 2000 | 6 | 6 |
| 2001 | 10 | 10 |
| 2002 | 51 | 51 |
| 2003 | 55 | 55 |
| 2004 | 153 | 153 |
| 2005 | 495 | 495 |
| 2006 | 1,281 | 1,281 |
| 2007 | 1,009 | 1,009 |
| 2008 | 1,544 | 1,544 |
| 2009 | 737 | 737 |
| 2010 | 620 | 620 |
| 2011 | 155 | 155 |
| 2012 | 266 | 266 |
| 2013 | 185 | 185 |
| 2014 | 283 | 283 |
| 2015 | 201 | 201 |
| 2016 | 142 | 142 |
| 2017 | 343 | 343 |
| 2018 | 509 | 509 |
| 2019 | 351 | 351 |
| 2020 | 462 | 462 |
| 2021 | 653 | 653 |
| 2022 | 649 | 649 |
| 2023 | 651 | 651 |
| 2024 | 735 | 735 |
| 2025 | 493 | 493 |
| 2026 | 423 | 423 |
suricata/<YYYY>/CVE-YYYY-NNNNN.rules # one file per CVE, one rule per line
nuclei/<YYYY>/CVE-YYYY-NNNNN.yaml # one template per CVE
payloads/ # self-hosted PoC payloads (SVG/DTD/CSV/…) so checks need no external host
scripts/ # validation tooling used by CI (run it locally too)
.github/ # CI workflows, issue forms, PR template
<YYYY> is the CVE year, not the year the signature was written.
Suricata (tested on Suricata 8.x):
cat suricata/*/*.rules > vedas.rules
suricata -T -c /etc/suricata/suricata.yaml -S vedas.rules # test-load first
Or add the directory to rule-files: in suricata.yaml. SIDs 1000000-1999999 come from VEDAS and 3000000-3999999 from the community. Neither range overlaps ET Open.
Nuclei (tested on Nuclei v3):
nuclei -t nuclei/ -u https://target.example
Only scan systems you are authorised to test.
Contributions of every kind are welcome:
| You want to... | Do this |
|---|---|
| Report a rule that fires on benign traffic | False positive issue |
| Report a rule that misses real exploitation | False negative issue |
| Report a rule that fails to load or is slow | Broken signature issue |
| Ask for coverage of a CVE | Signature request |
| Fix or add a signature | Open a pull request: see CONTRIBUTING.md |
Every pull request is checked automatically. It must load in real Suricata/Nuclei engines and pass the repository lint, and the target CVE must exist on cve.org. You can run the same checks locally before pushing (see CONTRIBUTING.md).
Signatures generated by VEDAS are syntactically validated only. Logical testing has not been performed in most cases. Validate every signature in your own environment before deploying it. Community-reviewed signatures are marked as such in their pull request history. This content is provided as-is, without warranty of any kind (see LICENSE).
Signatures are self-contained and on-prem friendly: every PoC payload a check needs is stored in payloads/ and served from this repository, with no dependency on any third-party host.
VEDAS aggregates openly available intelligence (OSINT) from across the internet — vulnerability databases, advisories, exploit and PoC publications, detection rulesets, and research shared by vendors, CERTs, independent researchers, and the wider cybersecurity community. This feed is built on that collective knowledge, and we're grateful to everyone who contributes to it. Where specific detection logic was adapted from an openly licensed project — notably projectdiscovery/nuclei-templates (MIT) — it is credited in NOTICE. Community contributors are credited in each template's info.author and in the pull-request history.
Please report security issues in this repository's tooling privately. See SECURITY.md.