🔍
Detection Rules — Sigma
Community-driven Sigma detection rules for SIEM and XDR platforms. Filter by severity level, status, and target product to find relevant rules for Windows, Linux, Azure, and cloud environments. Accelerate threat detection engineering.
Total Sigma Rules
3,737
104 stable · 3633 in test/experimental
Critical + High
1,886
174 critical · 1712 high
By Level
critical
174
high
1.7k
medium
1.5k
low
338
informational
28
🔍 Sigma Detection Rules7 results
Click row to view YAML · MITRE links clickable
🔍
MITRE
7 rules| Level | Title | Product / Category | MITRE Techniques | Status | Modified |
|---|---|---|---|---|---|
| high | ▸VBScript Payload Stored in Registry | windows / registry_set | test | 2023-08-17 | |
| high | ▸Scheduled Task Executing Encoded Payload from Registry | windows / process_creation | test | 2023-02-04 | |
| high | ▸Java Payload Strings | webserver | test | 2023-01-19 | |
| high | ▸Serpent Backdoor Payload Execution Via Scheduled Task | windows / process_creation | test | — | |
| medium | ▸Potential In-Memory Download And Compile Of Payloads | macos / process_creation | test | — | |
| medium | ▸Payload Decoded and Decrypted via Built-in Utilities | macos / process_creation | test | — | |
| medium | ▸Scheduled Task Executing Payload from Registry | windows / process_creation | test | — |