Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
53 rules
Suspicious Cobalt Strike DNS Beaconing (via dns)
criticalThis rule detects anomalous DNS queries known from Cobalt Strike beacons
sigmaNetworkPaid2026-03-04Suspicious FortiGate - New Local User Created (via event)
mediumThis rule detects the creation of a new local user on a Fortinet FortiGate Firewall. The new local user could be used for VPN connections.
sigmaNetwork2026-03-02Suspicious Cisco Clear Logs (via aaa)
highThis rule detects clear command history in network OS which is used for defense evasion
sigmaNetworkPaid2026-03-01Suspicious First Time Seen Remote Named Pipe - Zeek (via smb_files)
highThis rule detects this detection excludes known namped pipes accessible remotely and notify on newly observed ones, may help to detect lateral movement and remote exec using named pipes
sigmaNetworkPaid2026-02-19Suspicious FortiGate - Firewall Address Object Added (via event)
mediumThis rule detects the addition of firewall address objects on a Fortinet FortiGate Firewall.
sigmaNetwork2026-02-15Suspicious SMB Spoolss Name Piped Use (via smb_files)
mediumThis rule detects the use of the spoolss named pipe over SMB. This can be leveraged to trigger the authentication via NTLM of any machine that has the spoolservice enabled.
sigmaNetwork2026-02-11Possible DNS Events Related To Mining Pools (via dns)
lowThis rule detects clients that may be performing DNS lookups linked with common currency mining pools.
sigmaNetwork2026-02-08Suspicious FortiGate - VPN SSL Settings Modified (via event)
mediumThis rule detects the modification of VPN SSL Settings (for example, the modification of authentication rules). This behavior was observed in pair with the addition of a VPN SSL Web Portal.
sigmaNetwork2026-02-08Suspicious Monero Crypto Coin Mining Pool Lookup (via dns)
highThis rule detects anomalous DNS queries to Monero mining pools
sigmaNetworkPaid2026-02-03Suspicious Transferring Files with Credential Data through Network Shares - Zeek (via smb_files)
mediumThis rule detects transferring files with well-known filenames (sensitive files with credential data) using network shares
sigmaNetwork2026-01-20Possible Cisco LDP Authentication Failures (via ldp)
lowThis rule detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
sigmaNetwork2026-01-20Suspicious DNS Query Indicating Kerberos Coercion through DNS Object SPN Spoofing - Network (via dns)
highThis rule detects DNS queries containing patterns linked with Kerberos coercion attacks via DNS object spoofing. The pattern "1UWhRCAAAAA..BAAAA" is a base64-encoded signature that corresponds to a marshaled CREDENTIAL_TARGET_INFORMATION structure. Attackers can use this method to coerce authentication from victim systems to attacker-controlled hosts. It is one of the strong indicators of a Kerberos coercion attack, where threat actors manipulate DNS records to spoof Service Principal Names (SPNs) and redirect authentication requests like CVE-2025-33073.
sigmaNetworkPaid2026-01-07Suspicious Cisco Denial of Service (via aaa)
mediumThis rule detects a system being shutdown or put into different boot mode
sigmaNetwork2026-01-03