Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows DNS Queries Initiated by Regsvr32.exe
Flags DNS queries made by regsvr32.exe based on the querying process image path.
sigmaWindowsmedium2019-10-25Windows Security Event DCShadow Indicators via New Service Principal Name GC/
Flags Windows Security events where a servicePrincipalName starting with "GC/" is created, consistent with DCShadow-style SPN registration.
sigmaWindowsmedium2019-10-25Windows Security: New or Renamed User Account Name Containing '$'
Alerts on Windows user create/rename events when the account name contains '$', excluding the HomeGroupUser$ exception.
sigmaWindowsmedium2019-10-25Windows Process Creation: WSReset.exe Used with Non-CONHOST Child Process
Alerts when wsreset.exe spawns a process other than conhost.exe, a potential UAC-bypass precursor.
sigmaWindowshigh2019-10-24Windows: Detect Fodhelper.exe spawned processes indicative of UAC bypass
Flags process creation where the parent is Fodhelper.exe, a common UAC bypass execution pattern on Windows.
sigmaWindowshigh2019-10-24Windows: Command-line execution of cmstp.exe with INF install/silent/autobind flags (UAC bypass pattern)
Alerts when cmstp.exe is launched with INF installation and silent/auto options indicating a UAC-bypass style behavior.
sigmaWindowshigh2019-10-24Windows Process Creation: tapinstall.exe Execution
Alerts on tapinstall.exe being executed on Windows, excluding known VPN driver installer paths.
sigmaWindowsmedium2019-10-24Windows Process Creation: Web Request Cmdlets and CLI Tools Usage
Alerts on Windows CommandLine usage of web request cmdlets/tools like Invoke-WebRequest, Invoke-RestMethod, curl, wget, and BITS transfer.
sigmaWindowsmedium2019-10-24Windows Process Creation: LSASS .dmp/related Dump Keywords in Command Line
Alerts on Windows command lines containing LSASS dump keywords and .dmp/MDMP/zip/rar variants.
sigmaWindowshigh2019-10-24Windows Process Creation: SoundRecorder audio capture using /FILE
Flags SoundRecorder.exe launches that include /FILE, indicating potential audio capture on Windows.
sigmaWindowsmedium2019-10-24Windows System Time Discovery via net.exe or w32tm.exe
Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.
sigmaWindowslow2019-10-24Windows PowerShell Audio Capture Cmdlets: Toggle/Get/Set/Write AudioDevice
Flags PowerShell command lines referencing audio device cmdlets used to get/toggle/set/write audio device settings.
sigmaWindowsmedium2019-10-24Windows netsh Trace Start Command Execution
Flags netsh.exe launched with "trace" and "start", commonly used to begin a network trace capture on Windows.
sigmaWindowsmedium2019-10-24Windows Mshta.exe Launching JavaScript via Command Line
Detects Mshta.exe executions where the command line includes "javascript".
sigmaWindowshigh2019-10-24Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Alerts when Hwp.exe launches gbb.exe, a suspicious child process pattern on Windows.
sigmaWindowshigh2019-10-24Windows hh.exe Execution Triggered by .chm Command Line
Flags hh.exe being executed with a command line referencing a .chm file on Windows.
sigmaWindowslow2019-10-24Windows Domain Trust Discovery Using dsquery.exe TrustedDomain Queries
Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.
sigmaWindowsmedium2019-10-24Windows Execution of dnscat2 and iodine DNS Exfiltration/Tunneling Tools
Flags Windows execution of DNS tunneling/exfiltration tools identified by iodine.exe or dnscat2 in process creation events.
sigmaWindowshigh2019-10-24Windows Boot Configuration Tampering via bcdedit.exe
Flags bcdedit.exe commands that set boot status policy to ignore failures and disable recovery (recoveryenabled=no).
sigmaWindowshigh2019-10-24Windows at.exe Interactive Job via Process Creation
Alerts on at.exe process launches that include 'interactive' in the command line on Windows.
sigmaWindowshigh2019-10-24