Sigma Rule Library

Explore, search and understand Sigma detection rules

A fast, browsable library of community-maintained detection rules from theSigmaHQ repository — searchable by platform, log source, severity and MITRE ATT&CK.

3,783
Sigma rules
30
Products
171
ATT&CK techniques
2026-08-19
Last update

Browse by platform

Main logsource categories

Recently updated rules

What is the Sigma Rule Library?

Sigma Rule Library provides a searchable interface for exploring community-maintained Sigma detection rules from theSigmaHQ repository. Security analysts, detection engineers and threat hunters can browse rules by operating system, log source, severity, MITRE ATT&CK technique and rule status. Each rule page includes the original Sigma YAML, detection logic, metadata, references, false positives and links to related detections.

Explore Sigma detections

BrowseWindows,Linux, cloud, network and application detections, search by ATT&CK technique such asT1059 orT1003, and inspect the original rule before using it in your detection engineering workflow.