Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Live detection rule tracker

Is there a detection rule for this yet?

Search any CVE (e.g. CVE-2024-3400) or MITRE ATT&CK technique (e.g. T1190) and see instantly whether any of seven detection ecosystems — Sigma, Elastic, Splunk ESCU, YARA, Microsoft Sentinel, Snort, or Suricata — has shipped a rule for it, and how fresh that rule is.

59408 detection rules tracked · 22390 CVEs on file · 861 ATT&CK techniques · synced continuously
3763
Sigma rules
2194
Elastic rules
2175
Splunk ESCU
3028
YARA rules
482
Sentinel rules
23887
Snort rules
23879
Suricata rules
15045
Undetected CVEs (30d)
1476
Exploited & undetected

Recent coverage gaps

CVESeverityStatusPublished
CVE-2026-93952 CVSS 10.0 Actively exploited (KEV) 2026-09-22
CVE-2026-76460 CVSS 10.0 Actively exploited (KEV) 2026-09-16
CVE-2026-85706 CVSS 10.0 Actively exploited (KEV) 2026-09-12
CVE-2026-75650 CVSS 10.0 Actively exploited (KEV) 2026-09-07
CVE-2026-5430 CVSS 10.0 Actively exploited (KEV) 2026-08-06
CVE-2026-20079 CVSS 10.0 Actively exploited (KEV) 2026-03-04
CVE-2026-84869 CVSS 9.9 Actively exploited (KEV) 2026-09-08
CVE-2026-104286 CVSS 9.8 Actively exploited (KEV) 2026-10-01

See all coverage gaps →

Recently updated rules

Source Rule Status Updated
elastic Base64 Decoded Payload Piped to Interpreter production 2026-10-02
splunk Child Processes of Spoolsv exe deprecated 2026-10-02
sigma Renamed Schtasks Execution experimental 2026-10-02
suricata ET CINS Active Threat Intelligence Poor Reputation IP group 3 rev 112132 2026-10-01
suricata ET CINS Active Threat Intelligence Poor Reputation IP group 2 rev 112132 2026-10-01
suricata ET CINS Active Threat Intelligence Poor Reputation IP group 26 rev 112132 2026-10-01
suricata ET CINS Active Threat Intelligence Poor Reputation IP group 27 rev 112132 2026-10-01
suricata ET MALWARE PackClient RAT C2 Information Request rev 2 2026-10-01

Browse all detection rules →

Malware tracker

Curated profiles for well-known RAT, ransomware, and infostealer families, cross-referenced against every detection rule tracked here, with links to authoritative eradication guidance.

Browse all malware families →

Live detection rules from seven sources, in one place

Coverage, not just a rule dump

Every rule — SIEM detections, YARA malware signatures, and Snort/Suricata network signatures alike — is parsed for the CVEs and ATT&CK techniques it actually covers, so a lookup answers "is this covered" rather than handing you a search box full of raw rule files.

The gap list nobody else publishes

Recently published or actively exploited CVEs with zero matching rule across all seven sources — the shortlist worth writing custom detections for this week.

Freshness you can verify

Rule repos are re-synced continuously and every result carries its own last-updated date, so you can tell a rule shipped last week from one untouched since 2019.

Free public API

Every view is also JSON at /docs — wire coverage checks into your own triage tooling, dashboards, or CI without scraping this site.

Built for SOC analysts and detection engineering

Detection engineering runs on a question that is surprisingly hard to answer quickly: has anyone already written this rule? A CVE lands, it starts trending, and someone has to decide whether to spend the afternoon authoring a detection or whether SigmaHQ shipped one three days ago. Answering that by hand means searching several separate repositories, each with its own format, its own metadata conventions, and its own idea of how a CVE should be referenced — if it references one at all.

Sigma Watch does that lookup continuously instead. It tracks live detection rules from SigmaHQ, Elastic detection-rules, and Splunk ESCU for SIEM/EDR coverage, YARA for malware signatures, Microsoft Sentinel analytics rules, and the Snort/Suricata network signatures in Emerging Threats Open — normalizes all seven into one schema, and cross-references them against fresh CVE data from NVD and CISA's Known Exploited Vulnerabilities catalog plus the full MITRE ATT&CK technique catalog.

The result is two things a detection engineering team can act on immediately: a coverage lookup for any CVE or ATT&CK technique, and a running list of exploited vulnerabilities that still have no public detection rule anywhere. The second one is the interesting half — it is where your own rule-writing time is worth the most.

Sigma Watch reports only on these seven public sources. A CVE showing as a gap here may well be covered by a commercial vendor's private rule set — see About for exactly how coverage is determined and where the method has limits.

Who builds this

Motasem Hamdan
Cybersecurity content creator and instructor. I publish hands-on security training, walkthroughs, and practitioner study notes — Sigma Watch is the tool I wanted while doing detection work.

Enjoying Sigma Watch?

It is free, has no ads, and runs no third-party trackers. Keeping it synced against three rule repositories and the NVD feed costs real server time — if it saves you an afternoon, buy me a coffee.

☕ Support Sigma Watch