# Sigma Engine Array Extensions

Standard Sigma engines can't evaluate individual elements within arrays, which breaks detection logic for most cloud telemetry.

To address this, we’ve introduced [custom Sigma extensions](https://docs.alphasoc.com/detections_and_findings/sigma/supported_features/arrays/) for handling arrays in detection rules.

We’ve now extended this capability to support [OCSF fields](https://schema.ocsf.io/1.5.0/). Our array extensions can be used directly with OCSF schema paths, enabling portable detections that work across OCSF-normalized data sources, including audit logs (currently AWS CloudTrail and Okta Login).
