Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
53 rules
Possible Impacket SecretDump Remote Behavior - Zeek (via smb_files)
highThis rule detects AD credential dumping using impacket secretdump HKTL. Based on the SIGMA rules/windows/builtin/win_impacket_secretdump.yml
sigmaNetworkPaid2026-07-25Suspicious FortiGate - New Firewall Policy Added (via event)
mediumThis rule detects the addition of a new firewall policy on a Fortinet FortiGate Firewall.
sigmaNetwork2026-07-23Suspicious Wannacry Killswitch Domain (via dns)
highThis rule detects wannacry killswitch domain dns queries
sigmaNetworkPaid2026-07-21Possible PetitPotam Attack Through EFS RPC Calls (via dce_rpc)
mediumThis rule detects use of the windows RPC library Encrypting File System Remote Protocol (MS-EFSRPC). Variations of this RPC are used within the attack refereed to as PetitPotam. The use of this RPC function should be rare if ever used at all. Thus use of this function is uncommon enough that any use of this RPC function should warrant further investigation to determine if it is legitimate. View surrounding logs (within a few minutes before and after) from the Source IP to. Logs from from the Source IP would include dce_rpc, smb_mapping, smb_files, rdp, ntlm, kerberos, etc..'
sigmaNetwork2026-07-18Suspicious Execution of MITRE BZAR Indicators for (via dce_rpc)
mediumThis rule detects windows DCE-RPC functions which indicate an execution methods on the remote system. All credit for the Zeek mapping of the anomalous endpoint/operation field goes to MITRE
sigmaNetwork2026-07-17Suspicious Cisco Modify Configuration (via aaa)
mediumThis rule detects modifications to a config that will serve an adversary's impacts or persistence
sigmaNetwork2026-07-16Possible New Kind of Network (NKN) (via dns)
lowThis rule detects NKN is a networking service using blockchain technology to support a decentralized network of peers. While there are legitimate uses for it, it can also be used as a C2 channel. This rule looks for a DNS request to the ma>
sigmaNetwork2026-07-12HTTP Request to Low Reputation TLD or Suspicious File Extension (via http)
mediumThis rule detects HTTP requests to low reputation TLDs (e.g. .xyz, .top, .ru) or ending in anomalous file extensions (.exe, .dll, .hta), which may indicate hostile activity.
sigmaNetwork2026-07-10Possible Cisco Collect Data (via aaa)
lowThis rule detects collect pertinent data from the configuration files
sigmaNetwork2026-07-07Suspicious FortiGate - New Administrator Account Created (via event)
mediumThis rule detects the creation of an administrator account on a Fortinet FortiGate Firewall.
sigmaNetwork2026-07-04Possible Cleartext Protocol Use (via firewall)
lowThis rule detects ensure that all account usernames and authentication credentials are transmitted across networks using encrypted channels. Ensure that an encryption is used for all sensitive information in transit. Ensure that an encrypted channels is used for all administrative account access.
sigmaNetwork2026-07-04Suspicious Publicly Accessible RDP Service (via rdp)
highThis rule detects connections from routable IPs to an RDP listener. Which is indicative of a publicly-accessible RDP service.
sigmaNetworkPaid2026-07-02Suspicious Cisco Crypto Commands (via aaa)
highThis rule detects show when private keys are being exported from the device, or when new certificates are installed
sigmaNetworkPaid2026-06-28Suspicious FortiGate - New VPN SSL Web Portal Added (via event)
mediumThis rule detects the addition of a VPN SSL Web Portal on a Fortinet FortiGate Firewall. This behavior was observed in pair with modification of VPN SSL settings.
sigmaNetwork2026-06-24Suspicious Cisco File Removal (via aaa)
mediumThis rule detects see what files are being deleted from flash file systems
sigmaNetwork2026-06-24Suspicious Cisco Show Commands Input (via aaa)
mediumThis rule detects see what commands are being input into the device by other people, full credentials can be in the history
sigmaNetwork2026-06-22Suspicious DNS Query with B64 Encoded String (via dns)
mediumThis rule detects anomalous DNS queries using base64 encoding
sigmaNetwork2026-06-18Suspicious Telegram Bot API Request (via dns)
mediumThis rule detects anomalous DNS queries to api.telegram.org used by Telegram Bots of any kind
sigmaNetwork2026-06-17Suspicious FortiGate - User Group Modified (via event)
mediumThis rule detects the modification of a user group on a Fortinet FortiGate Firewall. The group could be used to grant VPN access to a network.
sigmaNetwork2026-06-15Suspicious Executable from Webdav (via http)
mediumThis rule detects executable access via webdav6. Can be seen in APT 29 such as from the emulated APT 29 hackathon https://github.com/OTRF/detection-hackathon-apt29/
sigmaNetwork2026-06-13