Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell ScriptBlock Web Request Cmdlets and Command-Line Tools
Alerts when PowerShell script blocks reference web request and download cmdlets/commands, excluding a specific guest configuration path.
sigmaWindowsmedium2019-10-24Windows: Uncommon Outbound Kerberos Traffic on Port 88
Alerts on initiated outbound connections to Kerberos TCP/88 from unexpected Windows processes.
sigmaWindowsmedium2019-10-24Windows PowerShell Profile File Creation or Modification
Alerts on creation or modification of PowerShell profile.ps1 files in typical Windows and PowerShell 7 locations.
sigmaWindowsmedium2019-10-24Windows Service Control Manager TAP Driver Installation (tap0901)
Flags Windows service installation events for TAP driver image paths containing 'tap0901'.
sigmaWindowsmedium2019-10-24Windows Security 4673: Failed LsaRegisterLogonProcess Handle Registration
Alerts on failed attempts to call LsaRegisterLogonProcess() in Windows Security (Event 4673), tied to the SeTcbPrivilege requirement.
sigmaWindowshigh2019-10-24Windows Security 4697: TAP Driver Service Installation (tap0901)
Alerts on Windows Security EID 4697 service installation events for TAP driver files containing "tap0901."
sigmaWindowslow2019-10-24Uncommon Outbound Kerberos Port 88 Network Connections (Windows Security Event 5156)
Alerts on rare outbound Kerberos (port 88) connections from non-browser/non-lsass processes using Windows Event 5156.
sigmaWindowsmedium2019-10-24Windows Security 4611: Rubeus-Indicative New Trusted Logon Process Registration
Alerts on Windows Security Event 4611 registering a new trusted logon process named 'User32LogonProcesss'.
sigmaWindowshigh2019-10-24Windows Registry COM Hijacking via TreatAs Subkey in CLSID
Alerts on registry modifications to HKU\Classes\CLSID\*\TreatAs that may indicate COM object hijacking/persistence.
sigmaWindowsmedium2019-10-23Windows: Sysmon filter driver unloaded using fltMC.exe
Identifies fltMC.exe commands attempting to unload the Sysmon filter driver via “unload sysmon”.
sigmaWindowshigh2019-10-23Windows Raw Disk Access by Uncommon Process Paths
Alerts on Windows raw disk access by processes from uncommon or suspicious locations.
sigmaWindowslow2019-10-22Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
sigmaWindowshigh2019-10-22Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands
Detects Windows processes using PowerShell/pwsh/wmic/vssadmin with shadow copy creation parameters.
sigmaWindowsmedium2019-10-22Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Flags reg.exe command lines exporting or saving HKLM registry hives tied to SAM, SYSTEM, and SECURITY.
sigmaWindowshigh2019-10-22Windows Process Execution Matching SILENTTRINITY Stager Metadata (st2stager)
Flags Windows process creation events containing "st2stager" in PE metadata, indicating SILENTTRINITY stager activity.
sigmaWindowshigh2019-10-22Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Flags Windows processes whose command lines contain Mimikatz names and credential-dumping module/function arguments.
sigmaWindowshigh2019-10-22Windows: Detect esentutl.exe Copying Sensitive Credential Files via VSS
Alerts on esentutl.exe VSS usage and command lines referencing SAM/SECURITY/SYSTEM or ntds.dit copy targets.
sigmaWindowshigh2019-10-22Windows Volume Shadow Copy Symlink Creation Using mklink
Flags Windows mklink commands that reference HarddiskVolumeShadowCopy to create symlinks.
sigmaWindowshigh2019-10-22Windows: Unsigned DLL/EXE Image Loaded Into lsass.exe
Alerts on image loads into lsass.exe where the loaded image is unsigned.
sigmaWindowsmedium2019-10-22Windows Static Webshell Indicators via Suspicious File Extension Creation in Web Roots
Alerts on Windows creation of script-like files with webshell extensions in web root directories, excluding common benign temp and XAMPP paths.
sigmaWindowsmedium2019-10-22