Sigma Rule Library

Platform / product

linux Sigma detection rules

248 community-maintained Sigma detection rules in the library target the linux platform, covering log sources such as process_creation, file_event, network_connection. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.

248 rules

Log sources

Severity