What the Sigma feed covers
The figures below are measured on the pack you download, not on our working repositories. No detection logic is published here.
Measured on the pack published on 2026-09-04 (manifest 2026.09.04) — 7,036 entries in total.
Platform
| Windows | 5,304 |
| Web & application | 906 |
| Cloud | 307 |
| Linux | 273 |
| Network | 137 |
| macOS | 81 |
| Containers | 16 |
| Security tooling | 7 |
| Unclassified | 5 |
Log type
| Process creation | 3,063 |
| Webserver | 795 |
| Registry set | 488 |
| File event | 392 |
| Ps script | 356 |
| Image load | 207 |
| Dns query | 115 |
| Network connection | 108 |
| Registry event | 84 |
| Application | 64 |
| Ps module | 60 |
| Proxy | 54 |
ATT&CK tactic
| Execution | 1,810 |
| Stealth | 1,715 |
| Persistence | 1,405 |
| Privilege escalation | 1,235 |
| Initial access | 1,139 |
| Defense impairment | 647 |
| Credential access | 621 |
| Command and control | 497 |
| Discovery | 412 |
| Lateral movement | 266 |
| Impact | 231 |
| Defense evasion | 196 |
| Collection | 189 |
| Exfiltration | 142 |
Severity
| High | 3,331 |
| Medium | 2,538 |
| Critical | 658 |
| Low | 471 |
| Informational | 38 |
Rule origin
| Open-source base, validated and converted | 5,971 |
| Written by ThreatClaw | 1,065 |
Rules compiled, per SIEM
Not every rule translates into every engine. Here is how many actually compile for each: that conversion work is precisely what you are buying.
| splunk | 6,998 |
| elastic | 6,995 |
| crowdstrike | 6,413 |
| qradar | 3,452 |
| panther | 2,921 |
| sentinel | 2,551 |