Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows System Service Creation of Obfuscated PowerShell IEX (Invoke-Obfuscation)
Flags Windows service creations whose ImagePath contains obfuscated PowerShell IEX invocation strings.
sigmaWindowshigh2019-11-08Windows Security: Detect Obfuscated PowerShell IEX Invocation via ServiceFileName Patterns (Event ID 4697)
Alerts on EventID 4697 instances where ServiceFileName matches obfuscated IEX-style PowerShell invocation patterns consistent with Invoke-Obfuscation.
sigmaWindowshigh2019-11-08Windows: Detect netsh.exe Commands Disabling Firewall
Flags netsh.exe executions that include command-line patterns used to disable Windows firewall.
sigmaWindowsmedium2019-11-01Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Flags PowerShell ScriptBlockText that combines Empire process-control indicators with dnscat DNS tunneling commands.
sigmaWindowscritical2019-11-01Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Alerts on Windows named pipe creations matching credential dumping tool pipe names.
sigmaWindowscritical2019-11-01Windows Credential Dump Tool Artifacts Written to Disk via File Events
Detects Windows file creation where the target filename contains or ends with known credential-dump tool or output names.
sigmaWindowshigh2019-11-01Windows Security: Suspicious AccessMask/AccessList Requested on LSASS (lsass.exe) Handle
Flags processes requesting potentially credential-dumping-related access to LSASS based on Security Event 4656/4663.
sigmaWindowsmedium2019-11-01Windows Security: Suspicious Local Account Created with ANONYMOUS LOGON SamAccountName
Alerts on Windows local account creation where the new SamAccountName contains “ANONYMOUS” and “LOGON”.
sigmaWindowshigh2019-10-31Windows PowerShell Script Execution from Alternate Data Stream (ADS)
Flags PowerShell processes using Get-Content -Stream to execute or retrieve script content from an ADS.
sigmaWindowshigh2019-10-30Windows Image Load: Unsigned dbghelp.dll/dbgcore.dll Loaded by Suspicious Process
Alerts on unsigned loading of dbghelp.dll/dbgcore.dll, often associated with memory dump creation and credential-access workflows.
sigmaWindowshigh2019-10-27Windows Remote Thread Creation Triggered by Uncommon Source Images
Detects remote thread creation on Windows when the SourceImage is one of several uncommon executables.
sigmaWindowsmedium2019-10-27Windows Remote Thread Creation from Uncommon Parent Image
Alerts on remote thread creation on Windows when the source executable is rare, with exclusions for known benign image pairings.
sigmaWindowshigh2019-10-27Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Alert on Windows executions where a SYSTEM-integrity child is spawned by a LOCAL SERVICE or NETWORK SERVICE parent, excluding a specific rundll32 pattern.
sigmaWindowshigh2019-10-26Windows: sc.exe Service Configuration Changed by Medium-Integrity Users
Alerts on sc.exe runs from Medium-integrity users that include service config/binPath or failure command changes.
sigmaWindowshigh2019-10-26Windows Service Configuration Tampering by Medium-Integrity Processes
Alerts on medium-integrity processes running commands that target registry service configuration values for potential privilege escalation.
sigmaWindowshigh2019-10-26Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
Alerts when services.exe spawns cmd/%COMSPEC% commands writing to a named pipe consistent with getsystem behavior.
sigmaWindowshigh2019-10-26Windows: DXCap.exe Used with -c to Launch Arbitrary Binaries
Flags Windows executions of DXCap.EXE using -c, a pattern that can launch arbitrary binaries or packages.
sigmaWindowsmedium2019-10-26Windows: Process Creation of Dnx.EXE May Indicate Application Whitelisting Bypass
Alerts on execution of dnx.exe, a .NET-based utility that can be abused to bypass application whitelisting.
sigmaWindowsmedium2019-10-26Windows: Suspicious Cdb.EXE Proxy Execution via Debugger Script Parameters
Alerts on cdb.exe starting with debugger script arguments that may be used to execute arbitrary commands.
sigmaWindowsmedium2019-10-26Windows: Uncommon Child Processes Spawned by Bginfo.exe
Flags unusual processes launched by Bginfo.exe/ Bginfo64.exe that may indicate abused proxy execution.
sigmaWindowsmedium2019-10-26