What the Sigma feed covers
The figures below are measured on the pack you download, not on our working repositories. No detection logic is published here.
Measured on the pack published on 2026-09-04 (manifest 2026.09.04) — 7 036 entries in total.
Plattform
| Windows | 5 304 |
| Web und Anwendung | 906 |
| Cloud | 307 |
| Linux | 273 |
| Netzwerk | 137 |
| macOS | 81 |
| Container | 16 |
| Sicherheitswerkzeuge | 7 |
| Nicht klassifiziert | 5 |
Protokolltyp
| Process creation | 3 063 |
| Webserver | 795 |
| Registry set | 488 |
| File event | 392 |
| Ps script | 356 |
| Image load | 207 |
| Dns query | 115 |
| Network connection | 108 |
| Registry event | 84 |
| Application | 64 |
| Ps module | 60 |
| Proxy | 54 |
ATT&CK-Taktik
| Execution | 1 810 |
| Stealth | 1 715 |
| Persistence | 1 405 |
| Privilege escalation | 1 235 |
| Initial access | 1 139 |
| Defense impairment | 647 |
| Credential access | 621 |
| Command and control | 497 |
| Discovery | 412 |
| Lateral movement | 266 |
| Impact | 231 |
| Defense evasion | 196 |
| Collection | 189 |
| Exfiltration | 142 |
Schweregrad
| High | 3 331 |
| Medium | 2 538 |
| Critical | 658 |
| Low | 471 |
| Informational | 38 |
Herkunft der Regeln
| Open-Source-Basis, validiert und konvertiert | 5 971 |
| Von ThreatClaw geschrieben | 1 065 |
Rules compiled, per SIEM
Not every rule translates into every engine. Here is how many actually compile for each: that conversion work is precisely what you are buying.
| splunk | 6 998 |
| elastic | 6 995 |
| crowdstrike | 6 413 |
| qradar | 3 452 |
| panther | 2 921 |
| sentinel | 2 551 |