Sigma Query Logo

> Sigma Rule Search Engine β€” precise Sigma rule search for practitioners

πŸ“Š Analytics πŸ”₯ Rankings πŸ—‚οΈ Discover Login Register
3,149 Total Rules
72 Critical
1,422 High Severity
77 Stable
391 MITRE ATT&CK
Votes Title Level Status Product Author Created
AWS Bedrock Guardrail Updated
Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety c...
medium experimental aws Marco Pedrinazzi (@pedrinazziM) (InTheCyber) 2026-07-27
AWS Bedrock Guardrail Deleted
Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety ...
medium experimental aws Marco Pedrinazzi (@pedrinazziM) (InTheCyber) 2026-07-27
AppLocker Application Would Have Been Blocked
Detects when AppLocker "Audit only" enforcement mode reports that an Application, DLL, Script, MSI, ...
medium experimental windows heyyanu 2026-07-09
Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog
Detects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method....
medium test windows Swachchhanda Shrawan Poudel (Nextron Systems) 2026-07-09
Azure Device No Longer Managed or Compliant
Identifies when a device in azure is no longer managed or compliant...
medium test azure Austin Songer @austinsonger 2026-07-03
Azure Service Principal Created
Identifies when a service principal is created in Azure....
medium test azure Austin Songer @austinsonger 2026-07-03
Disabled MFA to Bypass Authentication Mechanisms
Detection for when multi factor authentication has been disabled, which might indicate a malicious a...
medium test azure '@ionsor' 2026-07-03
Azure Service Principal Removed
Identifies when a service principal was removed in Azure....
medium test azure Austin Songer @austinsonger 2026-07-03
Azure Owner Removed From Application or Service Principal
Identifies when a owner is was removed from a application or service principal in Azure....
medium test azure Austin Songer @austinsonger 2026-07-03
User Added to an Administrator's Azure AD Role
User Added to an Administrator's Azure AD Role...
medium test azure RaphaΓ«l CALVET, @MetallicHack 2026-07-03
Azure Application Deleted
Identifies when a application is deleted in Azure....
medium test azure Austin Songer @austinsonger 2026-07-03
Antivirus - Exploitation Framework Signature
Detects a highly relevant Antivirus alert that reports an exploitation framework. This event must no...
critical stable - Florian Roth (Nextron Systems), Arnim Rupp 2026-07-01
Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
Detects the usage of SystemSettingsAdminFlows.exe to disable Windows Defender. SystemSettingsAdminFl...
high experimental - Chirag Damani (KPMG India), Swachchhanda Shrawan Poudel (Nextron Systems) 2026-07-01
Antivirus - Remote Access Tools Signature
Detects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ...
critical experimental - Arnim Rupp (Nextron Systems) 2026-07-01
Antivirus - APT Malware Signature
Detects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored j...
critical experimental - Arnim Rupp (Nextron Systems) 2026-07-01
New Agent Skills Installation Attempt Via Node.EXE
Detects the attempt to install new skills for AI agents using the "npx skills" command. Agent skills...
medium experimental windows Marco Pedrinazzi (@pedrinazziM) (InTheCyber) 2026-07-01
Process Execution From Shared Memory Directory
Detects the execution of a binary from the Linux shared memory directory /dev/shm. This directory is...
high experimental - Stan Beukers 2026-06-24
Curl File Upload To File Sharing Websites
Detects usage of curl to upload files to known file sharing domains, which may indicate data exfiltr...
high experimental - Swachchhanda Shrawan Poudel (Nextron Systems) 2026-06-24
Registry Enumeration via WMI Stdregprov
Detects the usage of wmic.exe to enumerate or read Windows registry via the WMI StdRegProv class rea...
medium experimental - Swachchhanda Shrawan Poudel (Nextron Systems) 2026-06-19
NTLM Hash Leak Via Curl NTLM Authentication
Detects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused t...
high test - Swachchhanda Shrawan Poudel (Nextron Systems) 2026-06-11
Clipboard Access Via OSAScript
Detects access to clipboard content via osascript, which may be used for data collection but also oc...
medium test macos Sohan G (D4rkCiph3r) 2026-06-11
Google Workspace MFA Disabled
Detects when multi-factor authentication (MFA) is disabled....
medium test gcp Austin Songer 2026-04-28
Google Workspace Application Access Level Modified
Detects when an access level is changed for a Google workspace application. An access level is part ...
medium test gcp Bryan Lim 2026-04-28
Google Workspace Role Modified or Deleted
Detects when an a role is modified or deleted in Google Workspace....
medium test gcp Austin Songer 2026-04-28
Google Workspace Application Removed
Detects when an an application is removed from Google Workspace....
medium test gcp Austin Songer 2026-04-28

🎯 MITRE ATT&CK Coverage Matrix

×

Loading...