🔍
Detection Rules — Sigma
Community-driven Sigma detection rules for SIEM and XDR platforms. Filter by severity level, status, and target product to find relevant rules for Windows, Linux, Azure, and cloud environments. Accelerate threat detection engineering.
Total Sigma Rules
3,737
104 stable · 3633 in test/experimental
Critical + High
1,886
174 critical · 1712 high
By Level
critical
174
high
1.7k
medium
1.5k
low
338
informational
28
🔍 Sigma Detection Rules7 results
Click row to view YAML · MITRE links clickable
🔍
MITRE
7 rules| Level | Title | Product / Category | MITRE Techniques | Status | Modified |
|---|---|---|---|---|---|
| critical | ▸Turla PNG Dropper Service | windows | test | 2021-11-30 | |
| critical | ▸Droppers Exploiting CVE-2017-11882 | windows / process_creation | stable | 2021-11-27 | |
| high | ▸WScript or CScript Dropper - File | windows / file_event | test | 2026-02-17 | |
| high | ▸Potential Winnti Dropper Activity | windows / file_event | test | 2023-01-05 | |
| high | ▸Mustang Panda Dropper | windows / process_creation | test | 2021-11-27 | |
| medium | ▸Potential Dropper Script Execution Via WScript/CScript/MSHTA | windows / process_creation | test | 2026-02-17 | |
| medium | ▸Potential Binary Or Script Dropper Via PowerShell | windows / file_event | — | test | 2025-07-04 |