Sigma Query Logo

> Sigma Rule Search Engine β€” precise Sigma rule search for practitioners

πŸ“Š Analytics πŸ”₯ Rankings πŸ—‚οΈ Discover Login Register
3,156 Total Rules
71 Critical
1,422 High Severity
77 Stable
391 MITRE ATT&CK
Votes Title Level Status Product Author Created
Windows AppX Deployment Full Trust Package Installation
Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated pr...
medium experimental windows Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems) 2026-09-03
Windows AppX Deployment Unsigned Package Installation
Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXD...
medium experimental windows Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems) 2026-09-03
New User Account Creation Attempt Via ADSI
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces) using...
medium experimental windows William Gokah (idea), Raylee Hawkins, Swachchhanda Shrawan Poudel (Nextron Systems) 2026-08-19
New User Account Creation Attempt Via ADSI in CommandLine
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patt...
medium experimental - William Gokah (idea), Raylee Hawkins, Swachchhanda Shrawan Poudel (Nextron Systems) 2026-08-19
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet an...
low experimental windows Tom3306 2026-08-19
Suspicious Machine Account Replication - DcSync Indicator
Detects suspicious Active Directory Replication Service (ADRS) requests originating from a machine a...
medium test windows Benjamin Delpy, Florian Roth (Nextron Systems), Scott Dermett, Sorina Ionescu 2026-08-05
Potentially Suspicious Explicit Credential Local Logon
Detects potentially suspicious explicit credential logon events where the user is trying to logon wi...
medium experimental windows Swachchhanda Shrawan Poudel (Nextron Systems) 2026-08-03
Potentially Suspicious Image Load of Offreg.dll
Detects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enab...
medium experimental - Swachchhanda Shrawan Poudel (Nextron Systems) 2026-08-03
Registry Hive File Staged Outside Standard User Profile Path
Detects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard us...
high experimental - Swachchhanda Shrawan Poudel (Nextron Systems) 2026-08-03
Suspicious Cross-User Process Spawn
Detects suspicious spawning of a process under a different user context than the parent process. Pro...
medium experimental - Swachchhanda Shrawan Poudel (Nextron Systems) 2026-08-03
AWS Bedrock Guardrail Updated
Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety c...
medium experimental aws Marco Pedrinazzi (@pedrinazziM) (InTheCyber) 2026-07-27
AWS Bedrock Guardrail Deleted
Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety ...
medium experimental aws Marco Pedrinazzi (@pedrinazziM) (InTheCyber) 2026-07-27
AppLocker Application Would Have Been Blocked
Detects when AppLocker "Audit only" enforcement mode reports that an Application, DLL, Script, MSI, ...
medium experimental windows heyyanu 2026-07-09
Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog
Detects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method....
medium test windows Swachchhanda Shrawan Poudel (Nextron Systems) 2026-07-09
User Added to an Administrator's Azure AD Role
User Added to an Administrator's Azure AD Role...
medium test azure RaphaΓ«l CALVET, @MetallicHack 2026-07-03
Azure Application Deleted
Identifies when a application is deleted in Azure....
medium test azure Austin Songer @austinsonger 2026-07-03
Disabled MFA to Bypass Authentication Mechanisms
Detection for when multi factor authentication has been disabled, which might indicate a malicious a...
medium test azure '@ionsor' 2026-07-03
Azure Device No Longer Managed or Compliant
Identifies when a device in azure is no longer managed or compliant...
medium test azure Austin Songer @austinsonger 2026-07-03
Azure Service Principal Created
Identifies when a service principal is created in Azure....
medium test azure Austin Songer @austinsonger 2026-07-03
Azure Service Principal Removed
Identifies when a service principal was removed in Azure....
medium test azure Austin Songer @austinsonger 2026-07-03
Azure Owner Removed From Application or Service Principal
Identifies when a owner is was removed from a application or service principal in Azure....
medium test azure Austin Songer @austinsonger 2026-07-03
Antivirus - Remote Access Tools Signature
Detects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ...
critical experimental - Arnim Rupp (Nextron Systems) 2026-07-01
Antivirus - APT Malware Signature
Detects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored j...
critical experimental - Arnim Rupp (Nextron Systems) 2026-07-01
Antivirus - Exploitation Framework Signature
Detects a highly relevant Antivirus alert that reports an exploitation framework. This event must no...
critical stable - Florian Roth (Nextron Systems), Arnim Rupp 2026-07-01
New Agent Skills Installation Attempt Via Node.EXE
Detects the attempt to install new skills for AI agents using the "npx skills" command. Agent skills...
medium experimental windows Marco Pedrinazzi (@pedrinazziM) (InTheCyber) 2026-07-01

🎯 MITRE ATT&CK Coverage Matrix

×

Loading...