Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Splunk RCE via User XSLT production 2026-05-14
splunk Detect New Open S3 Buckets over AWS CLI production 2026-05-13
splunk M365 Copilot Jailbreak Attempts production 2026-05-13
splunk M365 Copilot Agentic Jailbreak Attack production 2026-05-13
splunk M365 Copilot Information Extraction Jailbreak Attack production 2026-05-13
splunk Detect Excessive User Account Lockouts production 2026-05-13
snort ET ATTACK_RESPONSE EtherHiding Payload Delivery Script Observed Inbound rev 1 2026-05-13
suricata ET ATTACK_RESPONSE EtherHiding Payload Delivery Script Observed Inbound rev 1 2026-05-13
splunk Wmic NonInteractive App Uninstallation production 2026-05-13
splunk Wmiprvse LOLBAS Execution Process Spawn production 2026-05-13
splunk Wsmprovhost LOLBAS Execution Process Spawn production 2026-05-13
splunk WSReset UAC Bypass production 2026-05-13
splunk XSL Script Execution With WMIC production 2026-05-13
splunk Cisco Configuration Archive Logging Analysis production 2026-05-13
splunk Cisco IOS Suspicious Privileged Account Creation production 2026-05-13
splunk Cisco Network Interface Modifications production 2026-05-13
splunk Cisco Privileged Account Creation with HTTP Command Execution production 2026-05-13
splunk Cisco Privileged Account Creation with Suspicious SSH Activity production 2026-05-13
splunk Cisco SD-WAN - Arbitrary File Overwrite Exploitation Activity production 2026-05-13
splunk Cisco Secure Firewall - Blocked Connection production 2026-05-13
splunk Cisco SD-WAN - Low Frequency Rogue Peer production 2026-05-13
splunk Cisco SD-WAN - Peering Activity production 2026-05-13
splunk Cisco SD-WAN - Uncommon User-Agent Multi-URI Activity production 2026-05-13
splunk Cisco Secure Firewall - Bits Network Activity production 2026-05-13
splunk Cisco Secure Firewall - Citrix NetScaler Memory Overread Attempt production 2026-05-13
splunk Detect attackers scanning for vulnerable JBoss servers experimental 2026-05-13
splunk Detect malicious requests to exploit JBoss servers experimental 2026-05-13
splunk Detect Web Access to Decommissioned S3 Bucket experimental 2026-05-13
splunk Exploit Public Facing Application via Apache Commons Text production 2026-05-13
splunk Exploit Public-Facing Fortinet FortiNAC CVE-2022-39952 production 2026-05-13
splunk F5 TMUI Authentication Bypass production 2026-05-13
splunk Fortinet Appliance Auth bypass production 2026-05-13
splunk High Volume of Bytes Out to Url production 2026-05-13
splunk HTTP Duplicated Header production 2026-05-13
splunk HTTP Possible Request Smuggling production 2026-05-13
splunk Hunting for Log4Shell production 2026-05-13
splunk Ivanti Connect Secure Command Injection Attempts production 2026-05-13
splunk Ivanti Connect Secure SSRF in SAML Component production 2026-05-13
splunk Ivanti Connect Secure System Information Access via Auth Bypass production 2026-05-13
splunk Ivanti EPM SQL Injection Remote Code Execution production 2026-05-13