Sigma Rule Library

MITRE ATT&CK coverage

Rules in this catalog reference 171 of the 222 enterprise techniques in ATT&CK v19.2. Coverage reflects rule tags only — it does not claim complete detection coverage of any technique.

Download Navigator layer

Credential Access

16/17 techniques with rules

Defense Impairment

12/18 techniques with rules

Execution

14/20 techniques with rules

Impact

13/15 techniques with rules

Persistence

19/22 techniques with rules

Privilege Escalation

13/13 techniques with rules

Lateral Movement

7/9 techniques with rules

Stealth

23/30 techniques with rules

Exfiltration

6/9 techniques with rules
  • Automated ExfiltrationT1020

    10 rules →

  • Data Transfer Size LimitsT1030

    2 rules →

  • Exfiltration Over Alternative ProtocolT1048

    22 rules →

  • Exfiltration Over C2 ChannelT1041

    5 rules →

  • Exfiltration Over Other Network MediumT1011

    No rules

  • Exfiltration Over Physical MediumT1052

    No rules

  • Exfiltration Over Web ServiceT1567

    28 rules →

  • Scheduled TransferT1029

    No rules

  • Transfer Data to Cloud AccountT1537

    6 rules →

Discovery

29/34 techniques with rules

Collection

14/17 techniques with rules

Resource Development

5/9 techniques with rules

Reconnaissance

7/12 techniques with rules

Command and Control

13/18 techniques with rules

Initial Access

9/11 techniques with rules