Detection Catalogue · ATT&CK v19.2

Every rule, and where it came from.

The public catalogue of detection rules. Every entry carries the source it came from, the identifier it had there, the licence it was published under and its ATT&CK mapping.

No paywall and no sign-up wall. What a rule can show is decided by the licence it arrived under, not by whether you have an account.

11,341
published rules
4
sources
30,894
ATT&CK objects
45 minutes ago
last changed
Catalogue entryMedium
GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)

'This rule identifies a match Network Sessions for which the source or destination IP address is a known GreyNoise IoC. This analytic rule uses [ASIM](https://aka.ms/AboutASIM) and supports any built-in or custom source that supports the ASIM NetworkSession schema'

Source
Microsoft Sentinel analytics
Upstream
536e8e5c-ce0e-575e-bcc9-aba8e7bf9316
Licence
MIT License
ATT&CK
T1071
Version
01a0eb52-2096-7590-b239-c54aa174a81e
Published
Sep 29, 2026

Whether you can read the detection is not about you

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it. No account changes it either way.

Read the entry

Provenance

Nothing here arrived from nowhere.

Every rule keeps the identifier it had upstream and the licence it was published under. The counts are the catalogue's own.

The product

Four steps, and every one of them is the real thing.

Nothing below is a screenshot. Each canvas renders live catalogue data — the same records, the same provenance and the same detections you reach by pressing through.

What you can do

Everything the catalogue gives you.

The published catalogue needs no account. A free one adds what is computed over it: renderings for your SIEM, what changed between versions, and the analysis of its ATT&CK coverage.

Search and filterNo account
Search every published rule and narrow by severity, source, technique, author, platform or the log it needs.
Where each rule came fromNo account
Its source, the identifier it had there, its licence, its authors, the reports it cites and its known false positives.
ATT&CK matrixNo account
Every technique with the published rules that cover it, and the ones nothing covers yet.
Reports the rules citeNo account
For a published report, the detections that cite it.
Rendered for your SIEMFree account
Sigma rules rendered for Microsoft Sentinel, Splunk, IBM QRadar and Elastic, where the mapping allows.
What changedFree account
Every version of a published rule, and what changed from the one before.
CorroborationFree account
How many independent sources publish the same detection.
Coverage and gapsFree account
The catalogue's ATT&CK coverage, its gaps in order, and a layer for ATT&CK Navigator.

Not included

What it does not do yet.

  • Converting a rule of your own
  • Rendering rules that are not Sigma
  • Deploying to a SIEM

Start with a rule you already care about.

The catalogue needs nothing from you. A workspace is there when the detections become your own.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice