Boost Your SIEM with High-Quality Threat Detection Rules

Supercharge your Elastic Security capabilities with this comprehensive bundle of 1165 Sigma rules,
expertly converted for immediate use in your SIEM. Derived from the industry-standard SigmaHQ repository,
these Cybersecurity Rules provide robust coverage against a wide range of TTPs (Tactics, Techniques, and Procedures).

Designed for SOC analysts and threat hunters, this package helps you detect advanced threats, including Windows Security anomalies,
suspicious Process Creation, and potential Malware Detection events. The rules are provided as an
Importable NDJSON file, ready to be uploaded directly as Kibana Saved Objects.

Compatibility & Requirements

  • Platform: Elastic Stack (ELK) & Elastic Security
  • Versions: Compatible with Elastic Stack 8.x (8.0 – 8.17+) and Serverless
  • Format: Kibana Saved Objects (NDJSON)
  • Schema: Mapped to ECS (Elastic Common Schema)

Top MITRE ATT&CK Tactics Covered

This bundle offers significant depth across the MITRE ATT&CK framework. Key tactics covered include:

  • Defense Evasion: 600 rules
  • Execution: 329 rules
  • Privilege Escalation: 169 rules
  • Persistence: 150 rules
  • Credential Access: 111 rules

Installation Instructions

  1. Download the .zip file and extract the .ndjson file.
  2. Open Kibana and navigate to Stack Management > Saved Objects.
  3. Click Import and select the extracted NDJSON file.
  4. Ensure “Check for existing objects” is selected to avoid duplicates.
  5. Once imported, the rules will appear in the Security > Rules section, ready to be enabled.

Updated on February 15, 2026. Source: SigmaHQ.

Tested versions
ECS compliant

You must log in to submit a review.

Related downloads

Lens Conversion Rate

Lens conversion rate for RUM data using Lens Formulas

Vega advanced heat map

Vega example to show GitHub commits per author per hour of day.

APM Services overview canvas

Average rating:

An adaptive turn key canvas example based on Elastic APM data.

Google Cloud Log Ingestion dashboard

Canvas Board to analyze the log data collection of Google Cloud via Dataflow using the Google Cloud Metric module data

Watcher History Dashboard

This dashboard shows the history of executed watcher jobs.

These downloads could be also interesting for you

Watch for changes in IOWaits

A watch which alerts if the time spent by a hosts CPU in IOWait, has increased by more than than N% in the last Y mins.

ACSC Advisory IOCs detection rules

ACSC Advisory IOCs detection rules for Elastic SIEM

Azure billing data network

A vega visualization that shows the connection between resource group, resource type and the resource itself based on Elastic agent azure billing data integration.

SigmaHQ Rules Bundle (ECS) – 2026-02-15

Download 1165 Sigma rules for Elastic Security. Includes coverage for MITRE ATT&CK tactics like Execution and Defense Evasion. Compatible with Elastic Stack 8.x and Serverless.

Kibana Enhanced Table plugin

Data Table visualization with enhanced features like computed columns, pivot table or filter bar

Sigma Zeek Detection rules

A collection of rules based on the Sigma rules for Zeek based on the Filebeat Zeek module.