
> Sigma Rule Search Engine β precise Sigma rule search for practitioners
| Votes | Title | Level | Status | Product | Author | Created |
|---|---|---|---|---|---|---|
|
AWS Bedrock Guardrail Updated
Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety c... |
medium | experimental | aws | Marco Pedrinazzi (@pedrinazziM) (InTheCyber) | 2026-07-27 | |
|
AWS Bedrock Guardrail Deleted
Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety ... |
medium | experimental | aws | Marco Pedrinazzi (@pedrinazziM) (InTheCyber) | 2026-07-27 | |
|
AppLocker Application Would Have Been Blocked
Detects when AppLocker "Audit only" enforcement mode reports that an Application, DLL, Script, MSI, ... |
medium | experimental | windows | heyyanu | 2026-07-09 | |
|
Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog
Detects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method.... |
medium | test | windows | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-07-09 | |
|
Azure Device No Longer Managed or Compliant
Identifies when a device in azure is no longer managed or compliant... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Azure Service Principal Created
Identifies when a service principal is created in Azure.... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Disabled MFA to Bypass Authentication Mechanisms
Detection for when multi factor authentication has been disabled, which might indicate a malicious a... |
medium | test | azure | '@ionsor' | 2026-07-03 | |
|
Azure Service Principal Removed
Identifies when a service principal was removed in Azure.... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Azure Owner Removed From Application or Service Principal
Identifies when a owner is was removed from a application or service principal in Azure.... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
User Added to an Administrator's Azure AD Role
User Added to an Administrator's Azure AD Role... |
medium | test | azure | RaphaΓ«l CALVET, @MetallicHack | 2026-07-03 | |
|
Azure Application Deleted
Identifies when a application is deleted in Azure.... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Antivirus - Exploitation Framework Signature
Detects a highly relevant Antivirus alert that reports an exploitation framework. This event must no... |
critical | stable | - | Florian Roth (Nextron Systems), Arnim Rupp | 2026-07-01 | |
|
Windows Defender Disabled Via SystemSettingsAdminFlows.EXE
Detects the usage of SystemSettingsAdminFlows.exe to disable Windows Defender. SystemSettingsAdminFl... |
high | experimental | - | Chirag Damani (KPMG India), Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-07-01 | |
|
Antivirus - Remote Access Tools Signature
Detects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ... |
critical | experimental | - | Arnim Rupp (Nextron Systems) | 2026-07-01 | |
|
Antivirus - APT Malware Signature
Detects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored j... |
critical | experimental | - | Arnim Rupp (Nextron Systems) | 2026-07-01 | |
|
New Agent Skills Installation Attempt Via Node.EXE
Detects the attempt to install new skills for AI agents using the "npx skills" command. Agent skills... |
medium | experimental | windows | Marco Pedrinazzi (@pedrinazziM) (InTheCyber) | 2026-07-01 | |
|
Process Execution From Shared Memory Directory
Detects the execution of a binary from the Linux shared memory directory /dev/shm. This directory is... |
high | experimental | - | Stan Beukers | 2026-06-24 | |
|
Curl File Upload To File Sharing Websites
Detects usage of curl to upload files to known file sharing domains, which may indicate data exfiltr... |
high | experimental | - | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-06-24 | |
|
Registry Enumeration via WMI Stdregprov
Detects the usage of wmic.exe to enumerate or read Windows registry via the WMI StdRegProv class rea... |
medium | experimental | - | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-06-19 | |
|
NTLM Hash Leak Via Curl NTLM Authentication
Detects the use of curl with NTLM authentication and empty credentials (-u :), which can be abused t... |
high | test | - | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-06-11 | |
|
Clipboard Access Via OSAScript
Detects access to clipboard content via osascript, which may be used for data collection but also oc... |
medium | test | macos | Sohan G (D4rkCiph3r) | 2026-06-11 | |
|
Google Workspace MFA Disabled
Detects when multi-factor authentication (MFA) is disabled.... |
medium | test | gcp | Austin Songer | 2026-04-28 | |
|
Google Workspace Application Access Level Modified
Detects when an access level is changed for a Google workspace application. An access level is part ... |
medium | test | gcp | Bryan Lim | 2026-04-28 | |
|
Google Workspace Role Modified or Deleted
Detects when an a role is modified or deleted in Google Workspace.... |
medium | test | gcp | Austin Songer | 2026-04-28 | |
|
Google Workspace Application Removed
Detects when an an application is removed from Google Workspace.... |
medium | test | gcp | Austin Songer | 2026-04-28 |