Detection Rules
Real Sigma-style rules — MITRE ATT&CK mapping, required log fields, and how to turn on the audit setting that produces them.
cloud aws
email gateway
EMAIL-8001
Dangerous Attachment Type Delivered to a Mailbox
EMAIL-8002
Email Delivered Despite Failing DMARC Authentication
EMAIL-8003
Mass Phishing Campaign From a Single External Sender
EMAIL-8004
Executive/Brand Impersonation Email Delivered
EMAIL-8005
Large Outbound Attachment Sent to a Personal Webmail Domain
firewall
FW-7001
Port Scan / Network Reconnaissance from a Single Source
FW-7002
Large Outbound Data Transfer to an External Destination
FW-7003
Administrative Port Allowed Inbound from an Untrusted Zone
FW-7004
Repeated Blocked Outbound Connections Followed by a Successful One
FW-7005
Outbound Connection to a Known C2-Associated Port
linux
sysmon
waf
WAF-5001
SQL Injection Attempt Blocked
WAF-5002
Cross-Site Scripting Attempt Blocked
WAF-5003
Path Traversal / LFI Attempt Blocked
WAF-5004
Repeated WAF Blocks From the Same Source (Scanning/Probing)
WAF-5005
WAF Attack Signatures Followed by a Successful Login (Possible Successful Exploitation)
web server
web proxy
WEBPROXY-9001
Access to a Known-Malware Category URL Was Allowed
WEBPROXY-9002
Access to a Newly Registered Domain
WEBPROXY-9003
Repeated Requests to an Uncategorized Domain (Possible C2 Beaconing)
WEBPROXY-9004
Large File Upload to a File-Sharing Site
WEBPROXY-9005
Repeated Blocked Requests to a Domain Followed by a Successful One