What the Sigma feed covers
The figures below are measured on the pack you download, not on our working repositories. No detection logic is published here.
Measured on the pack published on 2026-09-04 (manifest 2026.09.04) — 7 036 entries in total.
Plataforma
| Windows | 5 304 |
| Web y aplicación | 906 |
| Nube | 307 |
| Linux | 273 |
| Red | 137 |
| macOS | 81 |
| Contenedores | 16 |
| Herramientas de seguridad | 7 |
| Sin clasificar | 5 |
Tipo de registro
| Process creation | 3 063 |
| Webserver | 795 |
| Registry set | 488 |
| File event | 392 |
| Ps script | 356 |
| Image load | 207 |
| Dns query | 115 |
| Network connection | 108 |
| Registry event | 84 |
| Application | 64 |
| Ps module | 60 |
| Proxy | 54 |
Táctica ATT&CK
| Execution | 1 810 |
| Stealth | 1 715 |
| Persistence | 1 405 |
| Privilege escalation | 1 235 |
| Initial access | 1 139 |
| Defense impairment | 647 |
| Credential access | 621 |
| Command and control | 497 |
| Discovery | 412 |
| Lateral movement | 266 |
| Impact | 231 |
| Defense evasion | 196 |
| Collection | 189 |
| Exfiltration | 142 |
Severidad
| High | 3 331 |
| Medium | 2 538 |
| Critical | 658 |
| Low | 471 |
| Informational | 38 |
Origen de las reglas
| Base open source, validada y convertida | 5 971 |
| Escritas por ThreatClaw | 1 065 |
Rules compiled, per SIEM
Not every rule translates into every engine. Here is how many actually compile for each: that conversion work is precisely what you are buying.
| splunk | 6 998 |
| elastic | 6 995 |
| crowdstrike | 6 413 |
| qradar | 3 452 |
| panther | 2 921 |
| sentinel | 2 551 |