Analytics

Field Explorer

Explore which fields are targeted in Sigma detections, how they're matched, and what values are most commonly used - per logsource. Useful for logging coverage planning, SIEM field mapping, and detection engineering.

71Logsources indexed
392Unique fields
3,707Rules analysed
Coverage

Global Modifier Usage

exact2,919
79% of rules use this modifier
endswith2,609
70% of rules use this modifier
contains2,281
62% of rules use this modifier
contains·all819
22% of rules use this modifier
startswith362
10% of rules use this modifier
regex118
3% of rules use this modifier
contains81
2% of rules use this modifier
CIDR25
1% of rules use this modifier

Logsource Explorer

1,398 rules in scope · 17 fields
contains·alladd27
contains\AppData\Local\Temp\24
containsrundll3222
containshttp21
contains:\Users\Public\18
contains\Users\Public\17
contains.dll17
containspowershell17
endswith\powershell.exe156
endswith\pwsh.exe144
endswith\cmd.exe115
endswith\rundll32.exe85
endswith\cscript.exe64
endswith\wscript.exe64
endswith\regsvr32.exe58
endswith\mshta.exe53
exactpwsh.dll76
exactPowerShell.EXE71
exactCmd.Exe39
exactwmic.exe35
exactRUNDLL32.EXE31
exactreg.exe30
exactnet.exe19
exactnet1.exe19
endswith\cmd.exe24
endswith\powershell.exe24
endswith\pwsh.exe21
endswith\wscript.exe18
endswith\cscript.exe16
endswith\rundll32.exe15
endswith\explorer.exe14
endswith\mshta.exe13
contains·all:\Users\3
contains/r2
contains\ProgramData\Microsoft\Windows Defender Advanced Threat Protection2
containsJwB7ACIAZgBhAGkAbABlAGQAIgA6AHQAcgB1AGUALAAiAG0AcwBnACIAOgAiAEEAbgBzAGkAYgBsAGUAIAByAGUAcQB1AGkAcgBlAHMAIABQAG8AdwBlAHIAUwBoAGUAbABsACAAdgAzAC4AMAAgAG8AcgAgAG4AZQB3AGUAcgAiAH0AJw2
containscAewAiAGYAYQBpAGwAZQBkACIAOgB0AHIAdQBlACwAIgBtAHMAZwAiADoAIgBBAG4AcwBpAGIAbABlACAAcgBlAHEAdQBpAHIAZQBzACAAUABvAHcAZQByAFMAaABlAGwAbAAgAHYAMwAuADAAIABvAHIAIABuAGUAdwBlAHIAIgB9ACcA2
containsnAHsAIgBmAGEAaQBsAGUAZAAiADoAdAByAHUAZQAsACIAbQBzAGcAIgA6ACIAQQBuAHMAaQBiAGwAZQAgAHIAZQBxAHUAaQByAGUAcwAgAFAAbwB3AGUAcgBTAGgAZQBsAGwAIAB2ADMALgAwACAAbwByACAAbgBlAHcAZQByACIAfQAnA2
contains:\Users\Public\2
contains:\Windows\Temp\2
exactGnuPG’s OpenPGP tool4
contains7-Zip3
exactCommand line RAR3
exactAnyDesk3
exactWindows PowerShell2
exactActive Directory Editor2
exactSystem activity monitor2
exactWMI Commandline Utility2
exactThe curl executable5
exactPowerShell Core 63
exactAnyDesk3
exactPing Castle2
containsNetSupport Remote Control2
exactRemote Utilities2
exactNode.js2
exactSQLite2
containsSHA256=2fb6c04c4f95fb8d158af94c137f90ac820716deaf88d8ebec956254e046cb292
containsSHA256=b3d21940a10fdef5e415ad70331ce257c24fe3bcf7722262302e0421791f87e82
containsSHA256=1fbd8362b2d2d2e6a5750ae3db69cd1815e6c1d31da48a98b796450971a8e0392
containsSHA256=0409c9b12f9d0eda86e461ed9bdabeefb00172b26322079681a0bdf48e68dc282
containsSHA256=7cfb411d04bac42ef93d1f0c93c0a481e38c6f4612b97ae89d4702595988edc72
containsSHA256=5b3c2d846ab162dc6bc595cce3a49de5731afde5d6060be7066d21b013a283732
containsSHA256=ce95df7f69664c3df19b76028e115931919a71517b776da7b42d353e2ff4a6702
containsSHA256=1293525a19cfe3bc8296b62fbfe19f083632ed644a1c18c10b045a1d3030d81a2
exactSystem24
exactS-1-16-1638424
exactHigh16
exactS-1-16-1228816
exactMedium3
exactS-1-16-81923
exactAnyDesk Software GmbH3
exactLogMeIn, Inc.2
exactMicrosoft Corporation1
containsSpecterOps1
containsevil corp1
exactCube0x01
exactSecurityXploded1
exactREvol Corp1
containsAUTHORI16
containsAUTORI16
endswith\SYSTEM1
endswith\Système1
endswith\СИСТЕМА1
containsTrustedInstaller1
containsNETWORK SERVICE1
containsNETZWERKDIENST1
contains\AppData\Local\Temp\1
contains\Desktop\1
contains\Downloads\1
contains\Users\Public\1
contains\Windows\Temp\1
exactc:\windows\system32\1
exactc:\windows\sysWOW64\1
exactC:\Program Files\Windows Defender\Offline\1
startswith7.0.1
startswith7.1.1
startswith8.0.11
startswith8.0.21
startswith8.0.31
startswith8.0.41
startswith8.0.51
startswith8.0.61
exact0x3e73
exactnull1
containsAUTHORI2
containsAUTORI2
endswith\NETWORK SERVICE1
endswith\LOCAL SERVICE1
exactSystemTraceProvider-Process1
endswith\rundll32.exe1