Sigma Rule Library

Platform / product

macos Sigma detection rules

75 community-maintained Sigma detection rules in the library target the macos platform, covering log sources such as process_creation, file_event. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.

75 rules

Log sources

Severity