Observed arrival · 2026-10-03
Sigma Watch maps detection rules to CVEs—and shows the gaps
A public security tool for checking whether detection rules from seven ecosystems cover a CVE or MITRE ATT&CK technique.
○Open
⊠Login
$Paid
†Ads
✦Pretty
●Pro
◎Niche
◉Human
⚑Risk
ƒJS
- For
- SOC analysts and detection engineers
- Worth noticing
- The homepage reports 14,768 CVEs as exploited and undetected within 30 days; its coverage counts are site-reported.
Field notes
The homepage presents counts by source, a recently updated rules list, and a separate list of recent coverage gaps; the displayed totals are site-reported. Its malware section describes RAT, ransomware, and infostealer profiles cross-referenced against the rules it tracks, with links to eradication guidance. The navigation also includes an API link and a Discord link.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
○OpenPublic substance visible
⊠LoginAccess appeared gated
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
One card from the complete issue