Sigma Rule Library

Log source category

antivirus log source Sigma rules

9 Sigma detection rules in the library use the antivirus log source. The antivirus category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.

9 rules

Severity