What the Sigma feed covers

The figures below are measured on the pack you download, not on our working repositories. No detection logic is published here.

Measured on the pack published on 2026-09-04 (manifest 2026.09.04)7,036 entries in total.

プラットフォーム

Windows5,304
Web・アプリ906
クラウド307
Linux273
ネットワーク137
macOS81
コンテナ16
セキュリティ製品7
未分類5

ログ種別

Process creation3,063
Webserver795
Registry set488
File event392
Ps script356
Image load207
Dns query115
Network connection108
Registry event84
Application64
Ps module60
Proxy54

ATT&CK 戦術

Execution1,810
Stealth1,715
Persistence1,405
Privilege escalation1,235
Initial access1,139
Defense impairment647
Credential access621
Command and control497
Discovery412
Lateral movement266
Impact231
Defense evasion196
Collection189
Exfiltration142

重大度

High3,331
Medium2,538
Critical658
Low471
Informational38

ルールの出所

OSS ベース(検証・変換済み)5,971
ThreatClaw 作成1,065

Rules compiled, per SIEM

Not every rule translates into every engine. Here is how many actually compile for each: that conversion work is precisely what you are buying.

splunk6 998
elastic6 995
crowdstrike6 413
qradar3 452
panther2 921
sentinel2 551
← Back to the Sigma feed