Detection Catalogue · ATT&CK v19.2
Every rule, and where it came from.
The public catalogue of detection rules. Every entry carries the source it came from, the identifier it had there, the licence it was published under and its ATT&CK mapping.
No paywall and no sign-up wall. What a rule can show is decided by the licence it arrived under, not by whether you have an account.
- 11,341
- published rules
- 4
- sources
- 30,894
- ATT&CK objects
- 45 minutes ago
- last changed
'This rule identifies a match Network Sessions for which the source or destination IP address is a known GreyNoise IoC. This analytic rule uses [ASIM](https://aka.ms/AboutASIM) and supports any built-in or custom source that supports the ASIM NetworkSession schema'
- Source
- Microsoft Sentinel analytics
- Upstream
- 536e8e5c-ce0e-575e-bcc9-aba8e7bf9316
- Licence
- MIT License
- ATT&CK
- T1071
- Version
- 01a0eb52-2096-7590-b239-c54aa174a81e
- Published
- Sep 29, 2026
Whether you can read the detection is not about you
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it. No account changes it either way.
Read the entryProvenance
Nothing here arrived from nowhere.
Every rule keeps the identifier it had upstream and the licence it was published under. The counts are the catalogue's own.
The product
Four steps, and every one of them is the real thing.
Nothing below is a screenshot. Each canvas renders live catalogue data — the same records, the same provenance and the same detections you reach by pressing through.
Search the public catalogue
- GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)Microsoft Sentinel analytics · MIT LicenseMediumT1071
- GreyNoise TI Map IP Entity to SigninLogsMicrosoft Sentinel analytics · MIT LicenseMediumT1071
- GreyNoise TI map IP entity to OfficeActivityMicrosoft Sentinel analytics · MIT LicenseMediumT1071
- GreyNoise TI Map IP Entity to DnsEventsMicrosoft Sentinel analytics · MIT LicenseMediumT1071
GreyNoise TI map IP entity to Network Session Events (ASIM Network Session schema)
Microsoft Sentinel analytics · MIT License · 536e8e5c-ce0e-575e-bcc9-aba8e7bf9316
'This rule identifies a match Network Sessions for which the source or destination IP address is a known GreyNoise IoC. This analytic rule uses [ASIM](https://aka.ms/AboutASIM) and supports any built-in or custom source that supports the ASIM NetworkSession schema'
Pivot through ATT&CK
- ReconnaissanceTA0043 · 46 techniques
- Resource DevelopmentTA0042 · 50 techniques
- Initial AccessTA0001 · 22 techniques
- ExecutionTA0002 · 64 techniques
- PersistenceTA0003 · 113 techniques
- Privilege EscalationTA0004 · 96 techniques
- StealthTA0005 · 148 techniques
- Defense ImpairmentTA0112 · 56 techniques
- Credential AccessTA0006 · 67 techniques
- DiscoveryTA0007 · 49 techniques
- Lateral MovementTA0008 · 23 techniques
- CollectionTA0009 · 41 techniques
- Command and ControlTA0011 · 45 techniques
- ExfiltrationTA0010 · 19 techniques
- ImpactTA0040 · 33 techniques
The catalogue is where detections are published. A workspace is where yours are written.
- 01Rules
- 02Versions
- 03Review
- 04Coverage
- 05Conversions
- 06Records
What each of those means is set out on the Workspace page.
What you can do
Everything the catalogue gives you.
The published catalogue needs no account. A free one adds what is computed over it: renderings for your SIEM, what changed between versions, and the analysis of its ATT&CK coverage.
- Search and filterNo account
- Search every published rule and narrow by severity, source, technique, author, platform or the log it needs.
- Where each rule came fromNo account
- Its source, the identifier it had there, its licence, its authors, the reports it cites and its known false positives.
- ATT&CK matrixNo account
- Every technique with the published rules that cover it, and the ones nothing covers yet.
- Reports the rules citeNo account
- For a published report, the detections that cite it.
- Rendered for your SIEMFree account
- Sigma rules rendered for Microsoft Sentinel, Splunk, IBM QRadar and Elastic, where the mapping allows.
- What changedFree account
- Every version of a published rule, and what changed from the one before.
- CorroborationFree account
- How many independent sources publish the same detection.
- Coverage and gapsFree account
- The catalogue's ATT&CK coverage, its gaps in order, and a layer for ATT&CK Navigator.
Works with
Where it leads.
Not included
What it does not do yet.
- Converting a rule of your own
- Rendering rules that are not Sigma
- Deploying to a SIEM
Start with a rule you already care about.
The catalogue needs nothing from you. A workspace is there when the detections become your own.