Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Windows Drivers Loaded by Signature production 2026-05-13
splunk Windows Guest Account Enabled Via Net.EXE production 2026-05-13
splunk Windows EFI Bootloader File Modification production 2026-05-13
splunk Windows EFI Volume Mount Attempt Via Mountvol production 2026-05-13
splunk Windows Enable PowerShell Web Access production 2026-05-13
splunk Windows Enable Win32 ScheduledJob via Registry production 2026-05-13
splunk Windows Entra User Management Via Azure CLI production 2026-05-13
splunk Windows ESX Admins Group Creation Security Event production 2026-05-13
splunk Windows ESX Admins Group Creation via Net production 2026-05-13
splunk Windows ESX Admins Group Creation via PowerShell production 2026-05-13
splunk Windows Event For Service Disabled production 2026-05-13
splunk Windows Event Logging Service Has Shutdown production 2026-05-13
splunk Windows Event Triggered Image File Execution Options Injection production 2026-05-13
splunk Windows EventLog Recon Activity Using Log Query Utilities production 2026-05-13
splunk Windows Excel Spawning Microsoft Project Application production 2026-05-13
splunk Windows Excessive Disabled Services Event production 2026-05-13
splunk Windows Excessive Service Stop Attempt production 2026-05-13
splunk Windows Excessive Usage Of Net App production 2026-05-13
splunk Windows Executable in Loaded Modules production 2026-05-13
splunk Windows Executable Masquerading as Benign File Types production 2026-05-13
splunk Windows Execute Arbitrary Commands with MSDT production 2026-05-13
splunk Windows Execution of Microsoft MSC File In Suspicious Path production 2026-05-13
splunk Windows Exfiltration Over C2 Via Invoke RestMethod production 2026-05-13
splunk Windows Exfiltration Over C2 Via Powershell UploadString production 2026-05-13
splunk Windows Explorer.exe Spawning PowerShell or Cmd production 2026-05-13
splunk Windows Explorer LNK Exploit Process Launch With Padding production 2026-05-13
splunk Windows Export Certificate production 2026-05-13
splunk Windows File and Directory Enable ReadOnly Permissions production 2026-05-13
splunk Windows File and Directory Permissions Enable Inheritance production 2026-05-13
splunk Windows File and Directory Permissions Remove Inheritance production 2026-05-13
splunk Windows File Association Modification via Ftype production 2026-05-13
splunk Windows Findstr GPP Discovery production 2026-05-13
splunk Windows File Collection Via Copy Utilities production 2026-05-13
splunk Windows File Share Discovery With Powerview production 2026-05-13
splunk Windows Gdrive Binary Activity production 2026-05-13
splunk Windows Files and Dirs Access Rights Modification Via Icacls production 2026-05-13
splunk Windows Filtering Platform Policy Added to Block EDR Process production 2026-05-13
splunk Windows Find Domain Organizational Units with GetDomainOU production 2026-05-13
splunk Windows Find Interesting ACL with FindInterestingDomainAcl production 2026-05-13
splunk Windows Firewall Rule Deletion production 2026-05-13