Is there a detection rule for this yet?
Search any CVE (e.g. CVE-2024-3400) or MITRE ATT&CK technique (e.g. T1190)
and see instantly whether any of seven detection ecosystems — Sigma, Elastic, Splunk ESCU, YARA, Microsoft
Sentinel, Snort, or Suricata — has shipped a rule for it, and how fresh that rule is.
Recent coverage gaps
| CVE | Severity | Status | Published |
|---|---|---|---|
| CVE-2026-93952 | CVSS 10.0 | Actively exploited (KEV) | 2026-09-22 |
| CVE-2026-76460 | CVSS 10.0 | Actively exploited (KEV) | 2026-09-16 |
| CVE-2026-85706 | CVSS 10.0 | Actively exploited (KEV) | 2026-09-12 |
| CVE-2026-75650 | CVSS 10.0 | Actively exploited (KEV) | 2026-09-07 |
| CVE-2026-5430 | CVSS 10.0 | Actively exploited (KEV) | 2026-08-06 |
| CVE-2026-20079 | CVSS 10.0 | Actively exploited (KEV) | 2026-03-04 |
| CVE-2026-84869 | CVSS 9.9 | Actively exploited (KEV) | 2026-09-08 |
| CVE-2026-104286 | CVSS 9.8 | Actively exploited (KEV) | 2026-10-01 |
Recently updated rules
| Source | Rule | Status | Updated |
|---|---|---|---|
| elastic | Base64 Decoded Payload Piped to Interpreter | production | 2026-10-02 |
| splunk | Child Processes of Spoolsv exe | deprecated | 2026-10-02 |
| sigma | Renamed Schtasks Execution | experimental | 2026-10-02 |
| suricata | ET CINS Active Threat Intelligence Poor Reputation IP group 34 | rev 112132 | 2026-10-01 |
| suricata | ET CINS Active Threat Intelligence Poor Reputation IP group 32 | rev 112132 | 2026-10-01 |
| suricata | ET CINS Active Threat Intelligence Poor Reputation IP group 33 | rev 112132 | 2026-10-01 |
| suricata | ET CINS Active Threat Intelligence Poor Reputation IP group 30 | rev 112132 | 2026-10-01 |
| suricata | ET CINS Active Threat Intelligence Poor Reputation IP group 28 | rev 112132 | 2026-10-01 |
Malware tracker
Curated profiles for well-known RAT, ransomware, and infostealer families, cross-referenced against every detection rule tracked here, with links to authoritative eradication guidance.
90 tracked
Gives an operator hands-on-keyboard remote control of an infected host - screen/webcam capture, keylogging, file access, and command execution.
94 tracked
Encrypts (and typically first exfiltrates) victim data, then extorts payment for a decryption key and/or a promise not to leak stolen files.
34 tracked
Harvests credentials, session cookies, and cryptocurrency wallet data from an infected host, usually for resale to other criminal operators.
Live detection rules from seven sources, in one place
Coverage, not just a rule dump
Every rule — SIEM detections, YARA malware signatures, and Snort/Suricata network signatures alike — is parsed for the CVEs and ATT&CK techniques it actually covers, so a lookup answers "is this covered" rather than handing you a search box full of raw rule files.
The gap list nobody else publishes
Recently published or actively exploited CVEs with zero matching rule across all seven sources — the shortlist worth writing custom detections for this week.
Freshness you can verify
Rule repos are re-synced continuously and every result carries its own last-updated date, so you can tell a rule shipped last week from one untouched since 2019.
Free public API
Every view is also JSON at /docs — wire coverage checks into your own triage tooling, dashboards, or CI without scraping this site.
Built for SOC analysts and detection engineering
Detection engineering runs on a question that is surprisingly hard to answer quickly: has anyone already written this rule? A CVE lands, it starts trending, and someone has to decide whether to spend the afternoon authoring a detection or whether SigmaHQ shipped one three days ago. Answering that by hand means searching several separate repositories, each with its own format, its own metadata conventions, and its own idea of how a CVE should be referenced — if it references one at all.
Sigma Watch does that lookup continuously instead. It tracks live detection rules from SigmaHQ, Elastic detection-rules, and Splunk ESCU for SIEM/EDR coverage, YARA for malware signatures, Microsoft Sentinel analytics rules, and the Snort/Suricata network signatures in Emerging Threats Open — normalizes all seven into one schema, and cross-references them against fresh CVE data from NVD and CISA's Known Exploited Vulnerabilities catalog plus the full MITRE ATT&CK technique catalog.
The result is two things a detection engineering team can act on immediately: a coverage lookup for any CVE or ATT&CK technique, and a running list of exploited vulnerabilities that still have no public detection rule anywhere. The second one is the interesting half — it is where your own rule-writing time is worth the most.
Sigma Watch reports only on these seven public sources. A CVE showing as a gap here may well be covered by a commercial vendor's private rule set — see About for exactly how coverage is determined and where the method has limits.
Who builds this
Enjoying Sigma Watch?
It is free, has no ads, and runs no third-party trackers. Keeping it synced against three rule repositories and the NVD feed costs real server time — if it saves you an afternoon, buy me a coffee.