Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Windows Unusual Count Of Users Failed To Auth Using Kerberos production 2026-05-13
splunk Windows Unusual Count Of Users Failed To Authenticate From Process production 2026-05-13
splunk Windows Unusual Count Of Users Failed To Authenticate Using NTLM production 2026-05-13
splunk Windows Unusual Count Of Users Remotely Failed To Auth From Host production 2026-05-13
splunk Windows Unusual NTLM Authentication Destinations By Source production 2026-05-13
splunk Windows Unusual NTLM Authentication Destinations By User production 2026-05-13
splunk Windows Unusual NTLM Authentication Users By Destination production 2026-05-13
splunk Windows Unusual NTLM Authentication Users By Source production 2026-05-13
splunk Windows USBSTOR Registry Key Modification production 2026-05-13
splunk Windows User Deletion Via Net production 2026-05-13
splunk Windows User Disabled Via Net production 2026-05-13
splunk Windows User Execution Malicious URL Shortcut File production 2026-05-13
splunk Windows Visual Basic Commandline Compiler DNSQuery production 2026-05-13
splunk Windows Vulnerable 3CX Software production 2026-05-13
splunk Windows WBAdmin File Recovery From Backup production 2026-05-13
splunk Windows WinDBG Spawning AutoIt3 production 2026-05-13
splunk Windows WinLogon with Public Network Connection production 2026-05-13
splunk Windows AD DSRM Password Reset production 2026-05-13
splunk Windows AD DSRM Account Changes production 2026-05-13
splunk Windows AD Domain Controller Promotion production 2026-05-13
splunk Windows AD Cross Domain SID History Addition production 2026-05-13
splunk Windows AD Abnormal Object Access Activity production 2026-05-13
splunk Windows Account Discovery With NetUser PreauthNotRequire production 2026-05-13
splunk Windows Account Discovery for Sam Account Name production 2026-05-13
splunk Windows Account Discovery for None Disable User Account production 2026-05-13
splunk Windows Account Access Removal via Logoff Exec production 2026-05-13
splunk Windows .Key File Creation in Root Directory production 2026-05-13
splunk Wermgr Process Spawned CMD Or Powershell Process production 2026-05-13
splunk Wermgr Process Create Executable File production 2026-05-13
splunk Web Servers Executing Suspicious Processes experimental 2026-05-13
splunk Web or Application Server Spawning a Shell production 2026-05-13
splunk Wbemprox COM Object Execution production 2026-05-13
splunk WBAdmin Delete System Backups production 2026-05-13
splunk Verclsid CLSID Execution production 2026-05-13
splunk USN Journal Deletion production 2026-05-13
splunk User Discovery With Env Vars PowerShell Script Block production 2026-05-13
splunk User Discovery With Env Vars PowerShell production 2026-05-13
splunk Unusually Long Command Line experimental 2026-05-13
splunk Unusual Number of Remote Endpoint Authentication Events experimental 2026-05-13
splunk Unusual Number of Kerberos Service Tickets Requested production 2026-05-13