Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry: DisableHypervisorEnforcedPagingTranslation Set to 1
Alerts when Windows disables Hypervisor Enforced Paging Translation by setting DisableHypervisorEnforcedPagingTranslation to 1.
sigmaWindowshigh2024-07-05Windows Registry: EnablePeriodicBackup value set for periodic system hive backups
Alerts on enabling the Windows registry setting that triggers periodic system hive backups to RegBack on restarts.
sigmaWindowsmedium2024-07-01Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Flags and image indicators for RemoteKrbRelay execution on Windows, including relaying-related command-line actions.
sigmaWindowshigh2024-06-27Windows File Drop Indicators for RemoteKrbRelay SMB Relay Secret Dump Module
Alerts on creation of RemoteKrbRelay-specific temp files used to stage secrets dump outputs on Windows.
sigmaWindowshigh2024-06-27Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
sigmaWindowshigh2024-06-26SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Flags SharpDPAPI executions on Windows by combining SharpDPAPI PE metadata with distinctive DPAPI-related CommandLine arguments.
sigmaWindowshigh2024-06-26Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
sigmaWindowshigh2024-06-26Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames
Alerts on Windows file events for DPAPI backup key/certificate filenames ending in .cer/.key/.pfx/.pvk.
sigmaWindowshigh2024-06-26Windows Process Execution: LaZagne Credential Dumping Utility (lazagne.exe)
Flags Windows process launches consistent with running LaZagne (lazagne.exe) for credential and password recovery.
sigmaWindowsmedium2024-06-24Windows Network Connections to azurewebsites.net from Non-Browser Processes
Alerts on outbound connections to azurewebsites.net started by non-browser processes on Windows.
sigmaWindowsmedium2024-06-24Windows File Creation: System DLL Named .dll in Uncommon Locations
Alerts on creation of .dll files named like system DLLs in unexpected Windows directories.
sigmaWindowsmedium2024-06-24Windows DNS Queries to azurewebsites.net From Non-Browser Processes
Alerts on DNS queries to azurewebsites.net from processes other than common browsers, using Windows DNS query and process image telemetry.
sigmaWindowsmedium2024-06-24Windows Network Connections to LocaltoNet/Localtonet Tunneling Subdomains
Alerts on initiated outbound connections from Windows hosts to LocaltoNet/.localtonet.com tunneling domains.
sigmaWindowshigh2024-06-17Windows: Suspicious Qemu execution with low-memory and network-tunneling flags
Alerts on Windows Qemu command lines using low -m values plus -netdev/connect= and -nographic.
sigmaWindowsmedium2024-06-03Windows Recall Enabled by Registry: DisableAIDataAnalysis Set to 0 (Windows)
Alerts when Windows Recall is enabled by setting the DisableAIDataAnalysis policy value to 0.
sigmaWindowsmedium2024-06-02Windows Recall Enabled by Deleting DisableAIDataAnalysis Registry Value
Flags deletion of WindowsAI\DisableAIDataAnalysis policy value indicating Windows Recall may be enabled.
sigmaWindowsmedium2024-06-02Windows Recall Enabled via reg.exe Registry Changes (Windows)
Flags reg.exe commands that delete or set DisableAIDataAnalysis to 0 under WindowsAI to enable Windows Recall.
sigmaWindowsmedium2024-06-02Windows Executable Connects to portmap.io Domain Over Network
Alerts when a Windows process initiates a connection to a .portmap.io destination hostname.
sigmaWindowsmedium2024-05-31Suspicious Web Browser Launch from PDF/Office Reader on Windows over HTTP(S)
Alerts when Acrobat/Office/PDF readers launch common browsers with HTTP(S) URLs, excluding known Microsoft and Foxit redirect patterns.
sigmaWindowsmedium2024-05-27Windows Process Access to Uncommon Target Images Using PROCESS_ALL_ACCESS
Alerts on Windows events granting PROCESS_ALL_ACCESS to processes with uncommon target image filenames.
sigmaWindowslow2024-05-27