🔍
Detection Rules — Sigma
Community-driven Sigma detection rules for SIEM and XDR platforms. Filter by severity level, status, and target product to find relevant rules for Windows, Linux, Azure, and cloud environments. Accelerate threat detection engineering.
Total Sigma Rules
3,737
104 stable · 3633 in test/experimental
Critical + High
1,886
174 critical · 1712 high
By Level
critical
174
high
1.7k
medium
1.5k
low
338
informational
28
🔍 Sigma Detection Rules12 results
Click row to view YAML · MITRE links clickable
🔍
MITRE
12 rules| Level | Title | Product / Category | MITRE Techniques | Status | Modified |
|---|---|---|---|---|---|
| critical | ▸CobaltStrike Named Pipe Pattern Regex | windows / pipe_created | test | 2026-06-18 | |
| critical | ▸CobaltStrike Service Installations - System | windows | test | 2022-11-27 | |
| critical | ▸CobaltStrike Named Pipe | windows / pipe_created | test | 2022-10-31 | |
| high | ▸Potential CobaltStrike Service Installations - Registry | windows / registry_set | test | 2024-03-25 | |
| high | ▸CobaltStrike Named Pipe Patterns | windows / pipe_created | test | 2024-01-26 | |
| high | ▸HackTool - CobaltStrike BOF Injection Pattern | windows / process_access | test | 2023-11-28 | |
| high | ▸HackTool - Potential CobaltStrike Process Injection | windows / create_remote_thread | test | 2023-05-05 | |
| high | ▸Potential CobaltStrike Process Patterns | windows / process_creation | test | 2023-03-29 | |
| high | ▸Potential Meterpreter/CobaltStrike Activity | windows / process_creation | test | 2023-02-05 | |
| high | ▸CobaltStrike Service Installations - Security | windows | test | 2022-11-27 | |
| high | ▸CobaltStrike Load by Rundll32 | windows / process_creation | test | 2022-09-16 | |
| high | ▸HackTool - CobaltStrike Malleable Profile Patterns - Proxy | proxy | test | — |