Sigma Rule Library

Platform / product

windows Sigma detection rules

2875 community-maintained Sigma detection rules in the library target the windows platform, covering log sources such as process_creation, registry_set, file_event, ps_script. Browse by severity, inspect the detection logic and MITRE ATT&CK mapping, and open the original Sigma YAML before using a rule in your detection engineering workflow.

2875 rules

Log sources

Severity