Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Security Audit: Registry Handle Write Access Requested for Defender Exclusions
Alerts on registry access requests with write/append permissions to Windows Defender exclusions key paths.
sigmaWindowsmedium2019-10-26Windows Registry: Windows Defender Exclusions Key Modified via ObjectName Match
Alerts on registry value changes under the Windows Defender Exclusions key in Windows Security event 4657.
sigmaWindowsmedium2019-10-26Windows Registry: Wow6432Node NT CurrentVersion Autorun Keys Modification
Alerts on registry modifications to Wow6432Node NT CurrentVersion autorun-related keys tied to persistence behavior.
sigmaWindowsmedium2019-10-25Windows Registry: Wow6432Node Classes Autorun/ASEP Key Modification via ShellEx/CLSID Paths
Alerts on registry writes to Wow6432Node Classes ASEP-related ShellEx/CLSID key paths commonly used for persistence.
sigmaWindowsmedium2019-10-25Windows Registry: Wow6432Node CurrentVersion Autorun Key Modification
Flags registry writes to Wow6432Node\...\CurrentVersion autostart and Explorer persistence locations, excluding common benign installer activity.
sigmaWindowsmedium2019-10-25Windows Registry WinSock2 Autostart Extensibility Point Modification
Flags registry modifications to WinSock2 Parameters catalog entries consistent with persistence via ASEP.
sigmaWindowsmedium2019-10-25Windows Registry Autostart Script Keys Modification via System Scripts Policies
Detects Registry writes to System Scripts policy ASEP subkeys for Startup/Shutdown/Logon/Logoff on Windows.
sigmaWindowsmedium2019-10-25Windows Registry Session Manager ASEP Modification via Auto-Start Extensibility Points
Flags registry modifications to Session Manager autostart extensibility points under CurrentControlSet\Control\Session Manager.
sigmaWindowsmedium2019-10-25Windows Registry Modification of Internet Explorer Autostart Extension Keys (ASEP)
Flags Windows registry changes to Internet Explorer ASEP extension/toolbar keys associated with persistence.
sigmaWindowsmedium2019-10-25Windows Registry: Modification of Windows NT CurrentVersion Autostart Extensibility Points
Alerts on Windows registry changes to Winlogon/ASEP-related keys under Windows NT CurrentVersion that may enable persistence.
sigmaWindowsmedium2019-10-25Windows Registry CurrentVersion Autostart/Run Key Modification Monitoring
Alerts on registry writes to Windows CurrentVersion autostart and Run/RunOnce persistence keys, excluding known benign patterns.
sigmaWindowsmedium2019-10-25Windows Registry CurrentControlSet Control Autorun/ASEP Key Modification
Alerts on Registry changes to Windows ASEP-related keys under CurrentControlSet\Control that can enable persistence.
sigmaWindowsmedium2019-10-25Windows Registry Autorun/ASEP Key Modification for Persistence
Alerts on registry modifications to common Windows autorun and persistence extensibility keys indicative of auto-start behavior.
sigmaWindowsmedium2019-10-25Windows Registry Classes Autorun Key Modification for Persistence
Alerts on registry changes under Windows Classes shell extension/ASEP paths that may enable persistence.
sigmaWindowsmedium2019-10-25Windows Registry: AppCertDlls NewName/TargetObject Creation for DLL Load Persistence
Alerts on Windows registry changes involving AppCertDlls paths that can enable malicious DLL loading for persistence.
sigmaWindowsmedium2019-10-25Windows Registry: Add-on DelegateExecute persistence via Narrator Feedback-Hub AppX key
Flags registry value deletions on a Narrator Feedback-Hub AppX DelegateExecute path used for persistence.
sigmaWindowshigh2019-10-25Windows: Registry CreateKey/Rename of HKLM\SYSTEM\CurrentControlSet\Control\MiniNt
Flags registry creation or renaming of the MiniNt key that can impair Windows event logging after reboot.
sigmaWindowshigh2019-10-25Windows reg.exe Direct Modification of Registry Autostart Extensibility Keys (ASEP)
Flags reg.exe adding registry autostart (ASEP) entries under common Run/Winlogon/Policy paths.
sigmaWindowsmedium2019-10-25Windows netsh.exe "add helper" execution for custom helper DLL loading
Flags netsh.exe being run with "add helper" parameters that can register a custom helper DLL.
sigmaWindowsmedium2019-10-25Windows Regsvr32.exe Initiated Network Connection
Flags outbound network connections initiated by Regsvr32.exe based on process image and connection initiation telemetry.
sigmaWindowsmedium2019-10-25