Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Creation of Shadow Copy production 2026-05-13
splunk Creation of Shadow Copy with wmic and powershell production 2026-05-13
splunk Credential Dumping via Copy Command from Shadow Copy production 2026-05-13
splunk Credential Dumping via Symlink to Shadow Copy production 2026-05-13
splunk Crowdstrike Admin Weak Password Policy production 2026-05-13
splunk Crowdstrike Admin With Duplicate Password production 2026-05-13
splunk CrowdStrike Falcon Stream Alerts production 2026-05-13
splunk Crowdstrike High Identity Risk Severity production 2026-05-13
splunk Crowdstrike Medium Severity Alert production 2026-05-13
splunk Crowdstrike Multiple LOW Severity Alerts production 2026-05-13
splunk Crowdstrike Privilege Escalation For Non-Admin User production 2026-05-13
splunk Crowdstrike User Weak Password Policy production 2026-05-13
splunk Crowdstrike User with Duplicate Password production 2026-05-13
splunk CSC Net On The Fly Compilation production 2026-05-13
splunk Detect Baron Samedit CVE-2021-3156 Segfault experimental 2026-05-13
splunk Curl Execution with Percent Encoded URL production 2026-05-13
splunk Delete ShadowCopy With PowerShell production 2026-05-13
splunk Deleting Shadow Copies production 2026-05-13
splunk Detect AzureHound Command-Line Arguments production 2026-05-13
splunk Detect AzureHound File Modifications production 2026-05-13
splunk Detect Baron Samedit CVE-2021-3156 experimental 2026-05-13
splunk Detect Baron Samedit CVE-2021-3156 via OSQuery experimental 2026-05-13
splunk Detect Certify Command Line Arguments production 2026-05-13
splunk Detect Certify With PowerShell Script Block Logging production 2026-05-13
splunk Detect Certipy File Modifications production 2026-05-13
splunk Detect Computer Changed with Anonymous Account production 2026-05-13
splunk Detect Copy of ShadowCopy with Script Block Logging production 2026-05-13
splunk Detect Empire with PowerShell Script Block Logging production 2026-05-13
splunk Detect Excessive Account Lockouts From Endpoint production 2026-05-13
splunk Detect Exchange Web Shell production 2026-05-13
splunk Detect HTML Help Using InfoTech Storage Handlers production 2026-05-13
splunk Detect Mimikatz With PowerShell Script Block Logging production 2026-05-13
splunk Detect mshta inline hta execution production 2026-05-13
splunk Detect New Local Admin account production 2026-05-13
splunk Detect Outlook exe writing a zip file production 2026-05-13
splunk Detect Password Spray Attack Behavior From Source production 2026-05-13
splunk Detect Password Spray Attack Behavior On User production 2026-05-13
splunk Detect Path Interception By Creation Of program exe production 2026-05-13
splunk Detect Prohibited Applications Spawning cmd exe production 2026-05-13
splunk Detect PsExec With accepteula Flag production 2026-05-13