Explore, search and understand Sigma detection rules
A fast, browsable library of community-maintained detection rules from theSigmaHQ repository — searchable by platform, log source, severity and MITRE ATT&CK.
- 3,783
- Sigma rules
- 30
- Products
- 171
- ATT&CK techniques
- 2026-08-19
- Last update
Browse by platform
Main logsource categories
Recently updated rules
Linux Webshell Indicators
highlinux · modified 2026-08-19
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
lowwindows · modified 2026-08-19
New User Account Creation Attempt Via ADSI
mediumwindows · modified 2026-08-13
New User Account Creation Attempt Via ADSI in CommandLine
mediumwindows · modified 2026-08-13
Uncommon New Firewall Rule Added In Windows Firewall Exception List
mediumwindows · modified 2026-08-06
Potentially Suspicious Mofcomp Execution
highwindows · modified 2026-08-06
ADCS - Certighost Ghost Machine Account Creation
highwindows · modified 2026-07-30
Suspicious Machine Account Replication - DcSync Indicator
mediumwindows · modified 2026-07-30
What is the Sigma Rule Library?
Sigma Rule Library provides a searchable interface for exploring community-maintained Sigma detection rules from theSigmaHQ repository. Security analysts, detection engineers and threat hunters can browse rules by operating system, log source, severity, MITRE ATT&CK technique and rule status. Each rule page includes the original Sigma YAML, detection logic, metadata, references, false positives and links to related detections.