Talk to the people behind the rules.
Ask about coverage, flag an issue or share an idea. Your message is read by a person and answered by email.
How a rule gets here
It starts from a named source
Every rule is built from public reporting — an incident write-up, a vendor advisory, a malware analysis — and that report is linked on the rule's own page.
A person checks it against that source
Before it is published a reviewer confirms the logic matches the behaviour described, the log source and prerequisites are stated, and the ATT&CK mapping is defensible rather than inflated.
Each rule says what it has earned
Reviewed means a person approved the logic and the metadata. Validated means it was additionally tested against a documented dataset. The two are never used interchangeably.