Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Disable UAC Remote Restriction production 2026-05-13
splunk Disable Show Hidden Files production 2026-05-13
splunk Disable Security Logs Using MiniNt Registry production 2026-05-13
splunk Disable Schedule Task production 2026-05-13
splunk Disable Registry Tool production 2026-05-13
splunk Disable Logs Using WevtUtil production 2026-05-13
splunk Disable ETW Through Registry production 2026-05-13
splunk Disable Defender Spynet Reporting production 2026-05-13
splunk Disable Defender MpEngine Registry production 2026-05-13
splunk Disable Defender Enhanced Notification production 2026-05-13
splunk Disable Defender BlockAtFirstSeen Feature production 2026-05-13
splunk Disable AMSI Through Registry production 2026-05-13
splunk Detection of tools built by NirSoft experimental 2026-05-13
splunk Detect Use of cmd exe to Launch Script Interpreters production 2026-05-13
splunk Detect SharpHound Usage production 2026-05-13
splunk Detect SharpHound File Modifications production 2026-05-13
splunk Detect SharpHound Command-Line Arguments production 2026-05-13
splunk Detect Rundll32 Inline HTA Execution production 2026-05-13
splunk Detect RTLO In Process production 2026-05-13
splunk Detect RTLO In File Name production 2026-05-13
splunk Detect Regsvr32 Application Control Bypass production 2026-05-13
splunk Detect Regsvcs with No Command Line Arguments production 2026-05-13
splunk Detect Regsvcs with Network Connection production 2026-05-13
splunk Detect Regsvcs Spawning a Process production 2026-05-13
splunk Detect Regasm with no Command Line Arguments production 2026-05-13
splunk Detect Regasm with Network Connection production 2026-05-13
splunk Detect Regasm Spawning a Process production 2026-05-13
splunk Detect Rare Executables production 2026-05-13
splunk Detect PsExec With accepteula Flag production 2026-05-13
splunk Detect Prohibited Applications Spawning cmd exe production 2026-05-13
splunk Detect Path Interception By Creation Of program exe production 2026-05-13
splunk Detect Password Spray Attack Behavior On User production 2026-05-13
splunk Detect Password Spray Attack Behavior From Source production 2026-05-13
splunk Detect Outlook exe writing a zip file production 2026-05-13
splunk Detect New Local Admin account production 2026-05-13
splunk Allow Inbound Traffic By Firewall Rule Registry production 2026-05-13
splunk Allow File And Printing Sharing In Firewall production 2026-05-13
splunk Advanced IP or Port Scanner Execution production 2026-05-13
splunk AdsiSearcher Account Discovery production 2026-05-13
splunk Add DefaultUser And Password In Registry production 2026-05-13