Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Windows System Discovery Using Qwinsta production 2026-05-13
splunk Windows System Discovery Using ldap Nslookup production 2026-05-13
splunk Windows System Binary Proxy Execution Compiled HTML File Decompile production 2026-05-13
splunk Windows Symlink Evaluation Change via Fsutil production 2026-05-13
splunk Windows SymbolicLink-Testing-Tools Utility Execution production 2026-05-13
splunk Windows Svchost.exe Parent Process Anomaly production 2026-05-13
splunk Windows Suspicious VMWare Tools Child Process production 2026-05-13
splunk Windows Suspicious QEMU Execution production 2026-05-13
splunk Windows Suspicious File in EFI Volume production 2026-05-13
splunk Windows Suspicious Driver Loaded Path production 2026-05-13
splunk Windows Suspicious Child Process Spawned From WebServer production 2026-05-13
splunk Windows Suspect Process With Authentication Traffic production 2026-05-13
splunk Windows SubInAcl Execution production 2026-05-13
splunk Windows Steal or Forge Kerberos Tickets Klist production 2026-05-13
splunk Windows Steal Authentication Certificates Export PfxCertificate production 2026-05-13
splunk Windows Steal Authentication Certificates Export Certificate production 2026-05-13
splunk Windows Steal Authentication Certificates CS Backup production 2026-05-13
splunk Windows Steal Authentication Certificates CertUtil Backup production 2026-05-13
splunk Windows Steal Authentication Certificates Certificate Request production 2026-05-13
splunk Windows Steal Authentication Certificates Certificate Issued production 2026-05-13
splunk Windows Steal Authentication Certificates - ESC1 Authentication production 2026-05-13
splunk Windows Steal Authentication Certificates - ESC1 Abuse production 2026-05-13
splunk Windows Steal Authentication Certificates CryptoAPI production 2026-05-13
splunk Windows SqlWriter SQLDumper DLL Sideload production 2026-05-13
splunk Windows Sqlservr Spawning Shell production 2026-05-13
splunk Windows SQLCMD Execution production 2026-05-13
splunk Windows SQL Spawning CertUtil experimental 2026-05-13
splunk Windows SQL Server xp_cmdshell Config Change production 2026-05-13
splunk Windows SQL Server Startup Procedure production 2026-05-13
splunk Windows Scheduled Task with Highest Privileges production 2026-05-13
splunk Windows Scheduled Task DLL Module Loaded production 2026-05-13
splunk Windows Scheduled Task Created Via XML production 2026-05-13
splunk Windows Scheduled Task Created in a Group Policy Object production 2026-05-13
splunk ESXi Syslog Config Change production 2026-05-13
splunk Windows RunMRU Registry Key or Value Deleted production 2026-05-13
splunk Windows RunMRU Command Execution production 2026-05-13
splunk Windows Rundll32 with Non-Standard File Extension production 2026-05-13
splunk Windows Rundll32 WebDav With Network Connection production 2026-05-13
splunk Windows Rundll32 WebDAV Request production 2026-05-13
splunk Windows Rundll32 Load DLL in Temp Dir production 2026-05-13