DETECTRASigma Rule Search Engine
NEXT RULE SYNCSYNC PENDING
BUY ME A COFFEE
OPEN DETECTION INTELLIGENCE
LIVE SIGMA INDEX3,949RULE FAMILIES · 8,160 IMPLEMENTATIONS
Critical 153High 1801Medium 1517Low 447Informational 31
SURFACES28PRODUCTS INDEXED
Windows3214Linux208Azure123
CONTRIBUTORS867AUTHORS INDEXED
Nasreddine Bencherchali (Nextron Systems)598Florian Roth (Nextron Systems)388frack113347

Turn Sigma into a SIEM-ready query.

Paste your own rule or send one directly from the detection index.

5 TARGETS READY
QUICK SEARCH
ALL RULES
3949 RULES MATCHING ALL SYSTEMS
PAGE 1 / 395
high4ae3e30b-b03f-43aa● test3 VARIANTS2026-09-25

Potential Arbitrary File Download Using Office Application

Detects potential arbitrary file download using a Microsoft Office application

Windowsattack.stealthattack.t1202
high7f734ed0-4f47-46c0● test2026-09-24

Potential Netcat Reverse Shell Execution

Detects execution of netcat with the "-e" or "-c" flags followed by common shells, which are commonly used to spawn reverse shells.

Linuxattack.executionattack.t1059
low96cd126d-f970-49c4● test2 VARIANTS2026-09-17

Potential PowerShell Obfuscation Using Alias Cmdlets

Detects Set-Alias or New-Alias cmdlet usage. Which can be use as a mean to obfuscate PowerShell scripts

Windowsattack.executionattack.stealth
critical2704ab9e-afe2-4854● test4 VARIANTS2026-09-16

HackTool - Dumpert Process Dumper Execution

Detects the use of Dumpert process dumper, which dumps the lsass.exe process memory

Windowsattack.credential-accessattack.t1003.001
mediuma1facc19-608b-ffb7● test4 VARIANTS2026-09-15

Elevated System Shell Spawned

Detects when a shell program such as the Windows command prompt or PowerShell is launched with system privileges. Use this rule to hunt for potential suspicious processes.

Windowsattack.privilege-escalationattack.execution
mediumd67081cb-334a-b0b2● test2026-09-15

LSASS Access From Program In Potentially Suspicious Folder

Detects process access to LSASS memory with suspicious access flags and from a potentially suspicious folder

Windowsattack.credential-accessattack.t1003.001
medium1bb242c0-2050-4e4d● test2026-09-15

Potential Shellcode Injection

Detects potential shellcode injection as seen used by tools such as Metasploit's migrate and Empire's psinject.

Windowsattack.privilege-escalationattack.stealth
medium38360161-76c4-4283● experimental2026-09-14

Suspicious Login Activity Classified By Google

Detects Google Workspace login activity that's classified as suspicious by Google.

GCPattack.initial-accessattack.privilege-escalation
medium612e47e9-8a59-43a6● test3 VARIANTS2026-08-31

ServiceDll Hijack

Detects changes to the "ServiceDLL" value related to a service in the registry. This is often used as a method of persistence.

Windowsattack.persistenceattack.privilege-escalation
highaff715fa-4dd5-497a● test2026-08-28

DNS Query to External Service Interaction Domains

Detects DNS queries to well-known out-of-band application security testing (OAST) and callback domains. These services (e.g. Burp Collaborator, interactsh, canarytokens, dnslog.cn) are used by security researchers and attackers alike to confirm blind vulnerabilities such as SSRF, XXE, blind RCE, and Log4Shell-style injections, where the exploit payload triggers an external DNS lookup to a controlled domain. A detection indicates that a host on your network resolved one of these domains, which may mean: (1) an attacker is actively probing or exploiting a vulnerable service and using the callback to confirm code execution or data exfiltration, (2) a security scanner (e.g. Nuclei, Gobies) is running against internal targets. Investigate the source host, the full DNS query string (the unique subdomain prefix encodes the callback session), and any concurrent outbound connections or process activity to determine intent.

Otherattack.initial-accessattack.t1190