Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk SQL Injection with Long URLs experimental 2026-05-13
splunk Wermgr Process Create Executable File production 2026-05-13
splunk Wermgr Process Spawned CMD Or Powershell Process production 2026-05-13
splunk Windows .Key File Creation in Root Directory production 2026-05-13
splunk Windows Account Access Removal via Logoff Exec production 2026-05-13
splunk Windows Account Discovery for None Disable User Account production 2026-05-13
splunk Windows Account Discovery for Sam Account Name production 2026-05-13
splunk Windows Account Discovery With NetUser PreauthNotRequire production 2026-05-13
splunk Windows AD Abnormal Object Access Activity production 2026-05-13
splunk Windows AD Cross Domain SID History Addition production 2026-05-13
splunk Windows AD Domain Controller Promotion production 2026-05-13
splunk Windows AD DSRM Account Changes production 2026-05-13
splunk Windows AD DSRM Password Reset production 2026-05-13
splunk Windows AD GPO Deleted production 2026-05-13
splunk Windows AD GPO Disabled production 2026-05-13
splunk Windows Anomalous Registry Value Length in Environment Key production 2026-05-13
splunk Windows Anonymous Pipe Activity production 2026-05-13
splunk Windows Apache Benchmark Binary production 2026-05-13
splunk Windows App Layer Protocol Qakbot NamedPipe production 2026-05-13
splunk Windows Application Layer Protocol RMS Radmin Tool Namedpipe production 2026-05-13
splunk Windows Application Whitelisting Bypass Attempt via Rundll32 production 2026-05-13
splunk Windows AppLocker Execution from Uncommon Locations production 2026-05-13
splunk Windows AppLocker Rare Application Launch Detection production 2026-05-13
splunk Windows AppX Deployment Full Trust Package Installation production 2026-05-13
splunk Windows AppX Deployment Package Installation Success production 2026-05-13
splunk Windows AppX Deployment Unsigned Package Installation production 2026-05-13
splunk Windows Archive Collected Data via Powershell production 2026-05-13
splunk Windows Archive Collected Data via Rar production 2026-05-13
splunk Windows Archived Collected Data In TEMP Folder production 2026-05-13
splunk Windows Audit Policy Auditing Option Disabled via Auditpol production 2026-05-13
splunk Windows Audit Policy Auditing Option Modified - Registry production 2026-05-13
splunk Windows Audit Policy Cleared via Auditpol production 2026-05-13
splunk Windows Audit Policy Disabled via Auditpol production 2026-05-13
splunk Windows Change File Association Command To Notepad production 2026-05-13
splunk Windows Chrome Auto-Update Disabled via Registry production 2026-05-13
splunk Windows Chrome Enable Extension Loading via Command-Line production 2026-05-13
splunk Windows Chrome Extension Allowed Registry Modification production 2026-05-13
splunk Windows Chromium Browser Launched with Small Window Size production 2026-05-13
splunk Windows Chromium process Launched with Disable Popup Blocking production 2026-05-13
splunk Windows Chromium Process Launched with Logging Disabled production 2026-05-13