Sigma Watch is free and independent. If it saves you time, keep it running. ☕ Buy me a coffee
SigmaWatch
Rule feed

Detection rules

Every rule tracked across all seven sources, newest updates first.

Source Rule Status Updated
elastic Cloud Credential Search Detected via Defend for Containers production 2026-09-18
elastic Sensitive File Compression Detected via Defend for Containers production 2026-09-18
elastic Sensitive Keys Or Passwords Search Detected via Defend for Containers production 2026-09-18
elastic Service Account Token or Certificate Read Detected via Defend for Containers production 2026-09-18
elastic Decoded Payload Piped to Interpreter Detected via Defend for Containers production 2026-09-18
elastic Shell Command-Line History Deletion Detected via Defend for Containers production 2026-09-18
elastic Ingress Tool Transfer Followed by Execution and Deletion Detected via Defend for Containers production 2026-09-18
elastic Suspicious Process Execution Detected via Defend for Containers production 2026-09-18
elastic Dynamic Linker Modification Detected via Defend for Containers production 2026-09-18
elastic Encoded Payload Detected via Defend for Containers production 2026-09-18
elastic DNS Enumeration Detected via Defend for Containers production 2026-09-18
elastic Environment Variable Enumeration Detected via Defend for Containers production 2026-09-18
elastic Kubelet Certificate File Access Detected via Defend for Containers production 2026-09-18
elastic Kubelet Pod Discovery Detected via Defend for Containers production 2026-09-18
elastic Potential Cluster Enumeration via jq Detected via Defend for Containers production 2026-09-18
elastic Privilege Boundary Enumeration Detected via Defend for Containers production 2026-09-18
elastic Service Account Namespace Read Detected via Defend for Containers production 2026-09-18
elastic Suspicious Network Tool Launch Detected via Defend for Containers production 2026-09-18
elastic Tool Enumeration Detected via Defend for Containers production 2026-09-18
elastic Container Management Utility Execution Detected via Defend for Containers production 2026-09-18
elastic Suspicious Container Runtime CLI Execution production 2026-09-18
elastic Direct Kubernetes API Request Detected via Defend for Containers production 2026-09-18
elastic Exec Into Container Detected via Defend for Containers production 2026-09-18
elastic File Creation and Execution Detected via Defend for Containers production 2026-09-18
elastic System Path File Creation and Execution Detected via Defend for Containers production 2026-09-18
elastic Interactive Shell Spawn Detected via Defend for Containers production 2026-09-18
elastic Potential Kubeletctl Execution Detected via Defend for Containers production 2026-09-18
elastic Netcat File Transfer or Listener Detected via Defend for Containers production 2026-09-18
elastic Payload Execution via Shell Pipe Detected by Defend for Containers production 2026-09-18
elastic Potential Direct Kubelet Access via Process Arguments Detected via Defend for Containers production 2026-09-18
elastic File Execution Permission Modification Detected via Defend for Containers production 2026-09-18
elastic Suspicious Interpreter Execution Detected via Defend for Containers production 2026-09-18
elastic Tool Installation Detected via Defend for Containers production 2026-09-18
elastic Process Killing Detected via Defend for Containers production 2026-09-18
elastic Modification of Persistence Relevant Files Detected via Defend for Containers production 2026-09-18
elastic SSH Authorized Key File Activity Detected via Defend for Containers production 2026-09-18
elastic Suspicious Echo or Printf Execution Detected via Defend for Containers production 2026-09-18
elastic Web Server Exploitation Detected via Defend for Containers production 2026-09-18
elastic Chroot Execution Detected via Defend for Containers production 2026-09-18
elastic DebugFS Execution Detected via Defend for Containers production 2026-09-18