Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
Flags Windows PowerShell remote session module context involving wsmprovhost.exe while filtering out archive module references.
sigmaWindowshigh2019-08-10Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
Flags Windows telemetry indicating a remote PowerShell session startup using wsmprovhost.exe with a specified host parameter.
sigmaWindowslow2019-08-10Windows Security: Network Access to protected_storage (IPC)
Flags Windows network share access to protected_storage through IPC from Security event 5145.
sigmaWindowshigh2019-08-10Windows Security Event 4692 Detecting DPAPI Domain Master Key Backup Attempt
Flags Windows Event ID 4692 indicating an attempt to back up the DPAPI domain master key.
sigmaWindowsmedium2019-08-10Windows: MMC spawning command-line executables
Flags cases where mmc.exe starts command-line tools like cmd, PowerShell, script hosts, or BITSADMIN.
sigmaWindowshigh2019-08-05Windows CMSTP UAC Bypass Attempt via Autoelevate COM Object DllHost Execution
Detects DllHost.exe spawning CMSTP-related autoelevate COM objects by matching known Processid values and high/system integrity.
sigmaWindowshigh2019-07-31Windows Security: AD object replication attempted by non-machine account (Event ID 4662)
Alerts on AD replication-related object access events where the requester is not a machine account.
sigmaWindowscritical2019-07-26Windows regsvr32 Executes DLL with Uncommon Extension in Command Line
Alerts when regsvr32.exe is launched with a DLL extension pattern that is not in the common list.
sigmaWindowsmedium2019-07-17Windows regsvr32 Usage of /i Without /n Flag
Alerts on regsvr32.exe invocations using /i: without the usually paired /n flag.
sigmaWindowsmedium2019-07-13Windows: Explorer factory invocation causing process tree break
Alerts on process creation command lines showing explorer.exe factory and /root usage consistent with an explorer-based process tree break.
sigmaWindowsmedium2019-06-29Windows Process Creation: Executable Extension Masquerading with .exe After Decoy Extension
Alerts on Windows processes whose paths/command lines use misleading double extensions ending in .exe to cloak executable execution.
sigmaWindowshigh2019-06-26Windows Security Log LSASS Access by Non-Computer Account Process
Alerts on suspicious LSASS access attempts (4663/4656) targeting lsass.exe by non-system processes using flagged access masks.
sigmaWindowsmedium2019-06-20Windows Security Event 4662 Detects DPAPI Domain Backup Key Extraction from Domain Controllers
Detects read access to LSA secret DPAPI domain backup key objects in Windows Event ID 4662.
sigmaWindowshigh2019-06-20Windows: Suspicious userinit.exe Child Process Creation
Alerts when userinit.exe spawns an atypical child process, excluding known benign explorer and netlogon command-line patterns.
sigmaWindowsmedium2019-06-17Windows Process Creation: Flag Renamed Execution of Common LOLBins Based on OriginalFileName
Alerts when a renamed process executes and Sysmon OriginalFileName matches common Windows LOLBins, suggesting defense-evasion rename behavior.
sigmaWindowshigh2019-06-15Windows Process Creation: Suspicious Renamed Binary Masquerading as Common Tools
Flags Windows executions where Sysmon OriginalFileName matches common tools but the process Image name ends differently.
sigmaWindowsmedium2019-06-15Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Flags Windows 4624 successful logons consistent with Pass-the-Hash activity using NtLmSsp or seclogo.
sigmaWindowsmedium2019-06-14Windows Process Creation: Renamed jusched.exe Execution via Java Scheduler Names
Alerts when Java Update Scheduler descriptions are used to execute a process ending with \jusched.exe on Windows.
sigmaWindowshigh2019-06-04Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Alerts when a new process is spawned under a Terminal Services (termsvcs) host context in Windows.
sigmaWindowshigh2019-05-22WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
sigmaWindowshigh2019-05-20