Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
splunk Windows RunMRU Registry Key or Value Deleted production 2026-05-13
splunk Windows Scheduled Task Created in a Group Policy Object production 2026-05-13
splunk Windows Scheduled Task Created Via XML production 2026-05-13
splunk Windows Scheduled Task DLL Module Loaded production 2026-05-13
splunk Windows Scheduled Task with Highest Privileges production 2026-05-13
splunk Windows Security Account Manager Stopped production 2026-05-13
splunk Windows Security And Backup Services Stop production 2026-05-13
splunk Windows Security Support Provider Reg Query production 2026-05-13
splunk Windows Sensitive Group Discovery With Net production 2026-05-13
splunk Windows Sensitive Registry Hive Dump Via CommandLine production 2026-05-13
splunk Windows Server Software Component GACUtil Install to GAC production 2026-05-13
splunk Windows Service Creation on Remote Endpoint production 2026-05-13
splunk Windows Service Creation Using Registry Entry production 2026-05-13
splunk Windows Service Deletion In Registry production 2026-05-13
splunk Windows Service Execution RemCom production 2026-05-13
splunk Windows Service Initiation on Remote Endpoint production 2026-05-13
splunk Windows Service Stop Attempt production 2026-05-13
splunk Windows Shell Process from CrushFTP production 2026-05-13
splunk Windows Short Lived DNS Record production 2026-05-13
splunk Windows SIP Provider Inventory production 2026-05-13
splunk Windows SIP WinVerifyTrust Failed Trust Validation production 2026-05-13
splunk Windows Snake Malware File Modification Crmlog production 2026-05-13
splunk Windows Snake Malware Kernel Driver Comadmin production 2026-05-13
splunk Windows Spearphishing Attachment Onenote Spawn Mshta production 2026-05-13
splunk Windows Special Privileged Logon On Multiple Hosts production 2026-05-13
splunk Windows SpeechRuntime COM Hijacking DLL Load production 2026-05-13
splunk Windows SpeechRuntime Suspicious Child Process production 2026-05-13
splunk Windows SQL Server Configuration Option Hunt production 2026-05-13
splunk Windows SQL Server Critical Procedures Enabled production 2026-05-13
splunk Windows Steal Authentication Certificates - ESC1 Abuse production 2026-05-13
splunk Windows Steal Authentication Certificates - ESC1 Authentication production 2026-05-13
splunk Windows Steal Authentication Certificates Certificate Issued production 2026-05-13
splunk Windows Steal Authentication Certificates Certificate Request production 2026-05-13
splunk Windows Application Layer Protocol RMS Radmin Tool Namedpipe production 2026-05-13
splunk Windows Application Whitelisting Bypass Attempt via Rundll32 production 2026-05-13
splunk Windows AppLocker Execution from Uncommon Locations production 2026-05-13
splunk Windows Archived Collected Data In TEMP Folder production 2026-05-13
splunk Windows Audit Policy Auditing Option Disabled via Auditpol production 2026-05-13
splunk Windows Audit Policy Auditing Option Modified - Registry production 2026-05-13
splunk Windows Audit Policy Cleared via Auditpol production 2026-05-13