SophiaX
🔍
LIVE
· New victim: sansilvestre.edu.pe — krybit· New victim: JMS Southeast — akira· New victim: Padget Technologies — akira· New victim: Delegal Poindexter & Underkofler, P.A. — morpheus· New victim: ISOPLUS — qilin· New KEV: CVE-2025-67038 · Lantronix· New KEV: CVE-2026-34908 · Ubiquiti· New KEV: CVE-2026-34910 · Ubiquiti· New KEV: CVE-2026-34909 · Ubiquiti· New KEV: CVE-2026-20253 · Splunk· New victim: 2,602 new IOCs ingested in last 24h sansilvestre.edu.pe — krybit· New victim: JMS Southeast — akira· New victim: Padget Technologies — akira· New victim: Delegal Poindexter & Underkofler, P.A. — morpheus· New victim: ISOPLUS — qilin· New KEV: CVE-2025-67038 · Lantronix· New KEV: CVE-2026-34908 · Ubiquiti· New KEV: CVE-2026-34910 · Ubiquiti· New KEV: CVE-2026-34909 · Ubiquiti· New KEV: CVE-2026-20253 · Splunk· 2,602 new IOCs ingested in last 24h
🔍

Detection Rules — Sigma

Community-driven Sigma detection rules for SIEM and XDR platforms. Filter by severity level, status, and target product to find relevant rules for Windows, Linux, Azure, and cloud environments. Accelerate threat detection engineering.

Total Sigma Rules
3,737
104 stable · 3633 in test/experimental
Critical + High
1,886
174 critical · 1712 high
By Level
critical
174
high
1.7k
medium
1.5k
low
338
informational
28
🔍 Sigma Detection Rules3,737 results
Click row to view YAML · MITRE links clickable
🔍
MITRE
3,737 rules
Page 1 / 75 · 150 of 3,737
LevelTitleProduct / CategoryMITRE TechniquesStatusModified
critical
CobaltStrike Named Pipe Pattern Regex
windows / pipe_createdtest2026-06-18
critical
Webshell Remote Command Execution
linuxtest2025-12-05
critical
Potential Dtrack RAT Activity
windows / process_creationstable2025-11-03
critical
HackTool - Windows Credential Editor (WCE) Execution
windows / process_creationtest2025-10-21
critical
Mint Sandstorm - ManageEngine Suspicious Process Execution
windows / process_creation
test2025-10-19
critical
Mint Sandstorm - AsperaFaspex Suspicious Process Execution
windows / process_creation
test2025-10-19
critical
Turla Group Commands May 2020
windows / process_creationtest2025-10-19
critical
WannaCry Ransomware Activity
windows / process_creationtest2025-10-18
critical
Potential SharePoint ToolShell CVE-2025-53770 Exploitation - File Create
windows / file_eventexperimental2025-07-24
critical
TrustedPath UAC Bypass Pattern
windows / process_creationtest2025-06-17
critical
WCE wceaux.dll Access
windowstest2025-01-30
critical
HackTool - Dumpert Process Dumper Execution
windows / process_creationtest2025-01-22
critical
Exploiting CVE-2019-1388
windows / process_creationstable2024-12-01
critical
Potential CVE-2021-41379 Exploitation Attempt
windows / process_creationtest2024-12-01
critical
Hacktool Execution - Imphash
windows / process_creationtest2024-11-23
critical
HackTool - SysmonEOP Execution
windows / process_creationtest2024-11-23
critical
Malicious DLL Load By Compromised 3CXDesktopApp
windows / image_load
test2024-11-23
critical
Antivirus Exploitation Framework Detection
antivirusstable2024-11-02
critical
Antivirus Ransomware Detection
antivirustest2024-11-02
critical
Antivirus Password Dumper Detection
antivirusstable2024-11-02
critical
HackTool - QuarksPwDump Dump File
windows / file_eventtest2024-06-27
critical
HackTool - Mimikatz Kirbi File Creation
windows / file_eventtest2024-06-27
critical
HackTool - Inveigh Execution Artefacts
windows / file_eventtest2024-06-27
critical
FlowCloud Registry Markers
windows / registry_eventtest2024-03-20
critical
HackTool - BabyShark Agent Default URL Pattern
proxytest2024-02-15
critical
Antivirus PrinterNightmare CVE-2021-34527 Exploit Detection
antivirusstable2023-10-23
critical
OceanLotus Registry Activity
windows / registry_eventtest2023-09-28
critical
Leviathan Registry Key Activity
windows / registry_eventtest2023-09-19
critical
CVE-2021-31979 CVE-2021-33771 Exploits
windows / registry_settest2023-08-17
critical
HackTool - Koh Default Named Pipe
windows / pipe_createdtest2023-08-07
critical
HackTool - DiagTrackEoP Default Named Pipe
windows / pipe_created
test2023-08-07
critical
HackTool - Credential Dumping Tools Named Pipe Created
windows / pipe_createdtest2023-08-07
critical
Malicious Named Pipe Created
windows / pipe_createdtest2023-08-07
critical
PrinterNightmare Mimikatz Driver Name
windows / registry_eventtest2023-06-12
critical
Qakbot Rundll32 Exports Execution
windows / process_creation
test2023-05-30
critical
HackTool - Dumpert Process Dumper Default File
windows / file_eventtest2023-05-09
critical
ProxyLogon Reset Virtual Directories Based On IIS Log
webservertest2023-05-08
critical
Moriya Rootkit File Created
windows / file_eventtest2023-05-05
critical
Mailbox Export to Exchange Webserver
windowstest2023-04-30
critical
Rorschach Ransomware Execution Activity
windows / process_creationtest2023-04-22
critical
HackTool - Rubeus Execution
windows / process_creationstable2023-04-20
critical
Silence.EDA Detection
windows / ps_scripttest2023-04-03
critical
CVE-2023-23397 Exploitation Attempt
windows
test2023-03-22
critical
APT31 Judgement Panda Activity
windows / process_creationtest2023-03-10
critical
Lazarus Group Activity
windows / process_creationtest2023-03-10
critical
Greenbug Espionage Group Indicators
windows / process_creationtest2023-03-09
critical
EvilNum APT Golden Chickens Deployment Via OCX Files
windows / process_creationtest2023-03-09
critical
APT27 - Emissary Panda Activity
windows / process_creationtest2023-03-09
critical
HAFNIUM Exchange Exploitation Activity
windows / process_creationtest2023-03-09
critical
Equation Group DLL_U Export Function Load
windows / process_creationstable2023-03-09