Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Network Share File Transfers Targeting Credential and Memory Dump Paths
Alerts on network share access to credential-related files using Windows Security Event 5145.
sigmaWindowsmedium2019-10-22Windows Network Tool Use for Possible Packet Sniffing (tshark/windump)
Alerts on Windows executions of tshark or windump that indicate potential passive network traffic capture.
sigmaWindowsmedium2019-10-21Windows Local Account Discovery via System Utilities Process Execution
Flags Windows processes that match utilities used to enumerate local user and account information.
sigmaWindowslow2019-10-21Windows: Detect sc.exe Service Config binPath Changes to Suspicious Commands/Paths
Alerts when sc.exe updates a service binPath to point at suspicious commands or commonly abused directories.
sigmaWindowshigh2019-10-21Windows reg.exe Registry Query Reconnaissance (Process Creation)
Alerts on reg.exe process executions performing registry queries against high-value configuration and service keys.
sigmaWindowsmedium2019-10-21Windows Rar.exe Files Added to Archive Activity
Alerts when Windows rar.exe is used to add files to an archive using the " a " command-line pattern.
sigmaWindowslow2019-10-21Windows: net.exe used to start a service with the start flag
Identifies Windows processes using net.exe/net1.exe with ' start ' to start services.
sigmaWindowslow2019-10-21Windows Msxsl.exe Execution
Flags execution of the Windows MSXSL utility (msxsl.exe), which can be abused to process attacker-controlled XSL inputs.
sigmaWindowsmedium2019-10-21Windows Process: File Association Changes via assoc Command
Alerts on cmd.exe launches running the assoc command to modify Windows default file associations.
sigmaWindowslow2019-10-21PowerShell ScriptBlock Winlogon Registry Modification via CurrentVersion\Winlogon
Detects PowerShell script blocks that modify Winlogon helper registry keys via Set-ItemProperty or New-Item on Windows.
sigmaWindowsmedium2019-10-21Windows Process Creation: Suspicious CHCP Code Page Switch to Rare Locale
Alerts on suspicious chcp.com usage that switches Windows code pages to specific rare identifiers in process creation logs.
sigmaWindowsmedium2019-10-14Windows Registry: Suspicious Keyboard Layout Preload in User Session
Detects user-hive registry changes that preload Persian (Iranian) or Vietnamese keyboard layouts under Windows.
sigmaWindowsmedium2019-10-12Windows Screen Capture via psr.exe (Problem Steps Recorder) Execution
Flags psr.exe launched with /start or -start, indicating potential user screen and click recording.
sigmaWindowsmedium2019-10-12Windows OpenWith.exe Launches Another Binary via /c
Flags Windows OpenWith.exe executions that include '/c', indicating it launched another binary.
sigmaWindowshigh2019-10-12Windows Devtoolslauncher.exe LaunchForDeploy Executes a Specified Binary
Alerts when devtoolslauncher.exe runs with LaunchForDeploy, indicating it may launch another binary on Windows.
sigmaWindowshigh2019-10-12Windows WMI Backdoor in Exchange Transport Agent via WMI Event Filter Execution
Alerts when WMI-backed execution is launched under EdgeTransport.exe, excluding common Exchange and conhost false positives.
sigmaWindowscritical2019-10-11PowerShell ScriptBlock uses rundll32 with shell32.dll and obfuscated invoke/comspec/iex
Flags PowerShell script blocks containing rundll32/shell32.dll execution strings alongside invoke/iex/comspec patterns.
sigmaWindowshigh2019-10-08PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
sigmaWindowshigh2019-10-08Windows Suspicious Run Key Created from Downloads or Outlook/IE Temporary Folders
Alerts on registry Run key writes originating from Downloads or temporary Outlook/IE directories on Windows.
sigmaWindowshigh2019-10-01Suspicious Windows Program Execution from Outlook Temporary Internet Files Folder
Alerts on process executions whose image path points to Outlook temporary files (Content.Outlook).
sigmaWindowshigh2019-10-01