Sigma Rule Library

Log source category

application log source Sigma rules

64 Sigma detection rules in the library use the application log source, mostly on opencanary, rpc_firewall, kubernetes. The application category groups related telemetry so you can find detections that consume the same events. Open a rule to read its detection logic, MITRE ATT&CK mapping and original YAML.

64 rules

Products

Severity