SophiaX
🔍
LIVE
· New victim: sansilvestre.edu.pe — krybit· New victim: JMS Southeast — akira· New victim: Padget Technologies — akira· New victim: Delegal Poindexter & Underkofler, P.A. — morpheus· New victim: ISOPLUS — qilin· New KEV: CVE-2025-67038 · Lantronix· New KEV: CVE-2026-34908 · Ubiquiti· New KEV: CVE-2026-34910 · Ubiquiti· New KEV: CVE-2026-34909 · Ubiquiti· New KEV: CVE-2026-20253 · Splunk· New victim: 2,653 new IOCs ingested in last 24h sansilvestre.edu.pe — krybit· New victim: JMS Southeast — akira· New victim: Padget Technologies — akira· New victim: Delegal Poindexter & Underkofler, P.A. — morpheus· New victim: ISOPLUS — qilin· New KEV: CVE-2025-67038 · Lantronix· New KEV: CVE-2026-34908 · Ubiquiti· New KEV: CVE-2026-34910 · Ubiquiti· New KEV: CVE-2026-34909 · Ubiquiti· New KEV: CVE-2026-20253 · Splunk· 2,653 new IOCs ingested in last 24h
🔍

Detection Rules — Sigma

Community-driven Sigma detection rules for SIEM and XDR platforms. Filter by severity level, status, and target product to find relevant rules for Windows, Linux, Azure, and cloud environments. Accelerate threat detection engineering.

Total Sigma Rules
3,737
104 stable · 3633 in test/experimental
Critical + High
1,886
174 critical · 1712 high
By Level
critical
174
high
1.7k
medium
1.5k
low
338
informational
28
🔍 Sigma Detection Rules7 results
Click row to view YAML · MITRE links clickable
🔍
MITRE
7 rules
LevelTitleProduct / CategoryMITRE TechniquesStatusModified
high
VBScript Payload Stored in Registry
windows / registry_settest2023-08-17
high
Scheduled Task Executing Encoded Payload from Registry
windows / process_creationtest2023-02-04
high
Java Payload Strings
webservertest2023-01-19
high
Serpent Backdoor Payload Execution Via Scheduled Task
windows / process_creationtest
medium
Potential In-Memory Download And Compile Of Payloads
macos / process_creationtest
medium
Payload Decoded and Decrypted via Built-in Utilities
macos / process_creationtest
medium
Scheduled Task Executing Payload from Registry
windows / process_creationtest