Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Windows System Discovery Using Qwinsta production 2026-05-13
splunk Windows System File on Disk production 2026-05-13
splunk Windows System LogOff Commandline production 2026-05-13
splunk Windows System Network Config Discovery Display DNS production 2026-05-13
splunk Windows System Reboot CommandLine production 2026-05-13
splunk Windows System Remote Discovery With Query production 2026-05-13
splunk Windows System Script Proxy Execution Syncappvpublishingserver production 2026-05-13
splunk Windows System Shutdown CommandLine production 2026-05-13
splunk Windows System Time Discovery W32tm Delay production 2026-05-13
splunk Windows System User Discovery Via Quser production 2026-05-13
splunk Windows System User Privilege Discovery production 2026-05-13
splunk Windows TeamCity Payload Execution from Temp Directory production 2026-05-13
splunk Windows TeamCity Plugin Installed production 2026-05-13
splunk Windows Theme File Creation in Unusual Location production 2026-05-13
splunk Windows Time Based Evasion via Choice Exec production 2026-05-13
splunk Windows TOR Client Execution production 2026-05-13
splunk Windows Unusual Intelliform Storage Registry Access production 2026-05-13
splunk Windows UAC Bypass Suspicious Child Process production 2026-05-13
splunk Windows UAC Bypass Suspicious Escalation Behavior production 2026-05-13
splunk Windows Universal Data Link File Creation production 2026-05-13
splunk Windows Unsigned DLL Side-Loading production 2026-05-13
splunk Windows Unsigned DLL Side-Loading In Same Process Path production 2026-05-13
splunk Windows Unsigned MS DLL Side-Loading production 2026-05-13
splunk Windows Unusual Count Of Disabled Users Failed Auth Using Kerberos production 2026-05-13
splunk Windows Unusual Count Of Invalid Users Fail To Auth Using Kerberos production 2026-05-13
splunk Windows Unusual Count Of Invalid Users Failed To Auth Using NTLM production 2026-05-13
splunk Windows Unusual Count Of Users Fail To Auth Wth ExplicitCredentials production 2026-05-13
splunk Windows Unusual Count Of Users Failed To Auth Using Kerberos production 2026-05-13
splunk Windows Unusual Count Of Users Failed To Authenticate From Process production 2026-05-13
splunk Windows Unusual Count Of Users Failed To Authenticate Using NTLM production 2026-05-13
splunk Windows Unusual Count Of Users Remotely Failed To Auth From Host production 2026-05-13
splunk Windows Unusual NTLM Authentication Destinations By Source production 2026-05-13
splunk Windows Unusual NTLM Authentication Destinations By User production 2026-05-13
splunk Windows Unusual NTLM Authentication Users By Destination production 2026-05-13
splunk Windows Unusual NTLM Authentication Users By Source production 2026-05-13
splunk Windows USBSTOR Registry Key Modification production 2026-05-13
splunk Windows User Deletion Via Net production 2026-05-13
splunk Windows User Disabled Via Net production 2026-05-13
splunk Windows User Execution Malicious URL Shortcut File production 2026-05-13
splunk Windows Visual Basic Commandline Compiler DNSQuery production 2026-05-13