🔍
Detection Rules — Sigma
Community-driven Sigma detection rules for SIEM and XDR platforms. Filter by severity level, status, and target product to find relevant rules for Windows, Linux, Azure, and cloud environments. Accelerate threat detection engineering.
Total Sigma Rules
3,764
104 stable · 3660 in test/experimental
Critical + High
1,897
176 critical · 1721 high
By Level
critical
176
high
1.7k
medium
1.5k
low
339
informational
28
🔍 Sigma Detection Rules6 results
Click row to view YAML · MITRE links clickable
🔍
MITRE
6 rules| Level | Title | Product / Category | MITRE Techniques | Status | Modified |
|---|---|---|---|---|---|
| high | ▸Emotet Loader Execution Via .LNK File | windows / process_creation | test | 2024-08-15 | |
| high | ▸Sofacy Trojan Loader Activity | windows / process_creation | test | 2023-05-31 | |
| high | ▸ChromeLoader Malware Execution | windows / process_creation | test | — | |
| high | ▸Lace Tempest Malware Loader Execution | windows / process_creation | — | test | — |
| high | ▸Injected Browser Process Spawning Rundll32 - GuLoader Activity | windows / process_creation | test | — | |
| medium | ▸DarkGate - Drop DarkGate Loader In C:\Temp Directory | windows / file_event | test | — |