Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Crowdstrike Privilege Escalation For Non-Admin User production 2026-05-13
splunk Crowdstrike User Weak Password Policy production 2026-05-13
splunk Crowdstrike User with Duplicate Password production 2026-05-13
splunk CSC Net On The Fly Compilation production 2026-05-13
splunk Detect Baron Samedit CVE-2021-3156 Segfault experimental 2026-05-13
splunk Curl Execution with Percent Encoded URL production 2026-05-13
splunk Delete ShadowCopy With PowerShell production 2026-05-13
splunk Deleting Shadow Copies production 2026-05-13
splunk Detect AzureHound Command-Line Arguments production 2026-05-13
splunk Detect AzureHound File Modifications production 2026-05-13
splunk Detect Baron Samedit CVE-2021-3156 experimental 2026-05-13
splunk Detect Baron Samedit CVE-2021-3156 via OSQuery experimental 2026-05-13
splunk Detect Certify Command Line Arguments production 2026-05-13
splunk Detect Certify With PowerShell Script Block Logging production 2026-05-13
splunk Detect Certipy File Modifications production 2026-05-13
splunk Detect Computer Changed with Anonymous Account production 2026-05-13
splunk Detect Copy of ShadowCopy with Script Block Logging production 2026-05-13
splunk Detect Empire with PowerShell Script Block Logging production 2026-05-13
splunk Detect Excessive Account Lockouts From Endpoint production 2026-05-13
splunk Detect Exchange Web Shell production 2026-05-13
splunk Detect HTML Help Using InfoTech Storage Handlers production 2026-05-13
splunk Detect Mimikatz With PowerShell Script Block Logging production 2026-05-13
splunk Detect mshta inline hta execution production 2026-05-13
splunk Windows Impair Defense Override SmartScreen Prompt production 2026-05-13
splunk Disabled Kerberos Pre-Authentication Discovery With Get-ADUser production 2026-05-13
splunk Disabled Kerberos Pre-Authentication Discovery With PowerView production 2026-05-13
splunk Disabling CMD Application production 2026-05-13
splunk Disabling ControlPanel production 2026-05-13
splunk Disabling Defender Services production 2026-05-13
splunk Disabling Firewall with Netsh production 2026-05-13
splunk Disabling FolderOptions Windows Feature production 2026-05-13
splunk Disabling NoRun Windows App production 2026-05-13
splunk Disabling Remote User Account Control production 2026-05-13
splunk Disabling SystemRestore In Registry production 2026-05-13
splunk Disabling Task Manager production 2026-05-13
splunk Disabling Windows Local Security Authority Defences via Registry production 2026-05-13
splunk DLLHost with no Command Line Arguments with Network production 2026-05-13
splunk DNS Exfiltration Using Nslookup App production 2026-05-13
splunk Domain Account Discovery with Dsquery production 2026-05-13
splunk Domain Account Discovery with Wmic production 2026-05-13