Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell Script Block Logging: Nishang Commandlet Names and Arguments
High-severity alert on PowerShell script blocks that reference known Nishang commandlets and exfil/execution helper names.
sigmaWindowshigh2019-05-16Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes
Alerts on outbound port 3389 connections on Windows when initiated by an unapproved process, suggesting non-standard RDP tooling.
sigmaWindowshigh2019-05-15Windows PowerShell Process Creation With Empire-Style EncodedCommand Launch Parameters
Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.
sigmaWindowshigh2019-04-20Windows Local User Creation (Security Event 4720)
Flags Windows Security Event ID 4720 indicating a local user account was created.
sigmaWindowslow2019-04-18Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
sigmaWindowshigh2019-04-15Windows: Suspicious Service Installation via Registry ImagePath Outside system32
Alerts on NalDrv/PROCEXP152 service ImagePath registry entries configured outside the expected system32 driver path.
sigmaWindowsmedium2019-04-08Windows Suspicious PROCEXP152.sys Creation in Local Temp Folder
Flags creation of PROCEXP152.sys in AppData\Local\Temp, excluding events from common Sysinternals executables.
sigmaWindowsmedium2019-04-08Windows Security Event 4673: SeLoadDriverPrivilege Use by Non-Whitelisted Processes
Flags Windows Event 4673 instances where SeLoadDriverPrivilege is exercised, suggesting attempts to load or unload kernel-mode drivers.
sigmaWindowsmedium2019-04-08WmiPrvSE.exe Spawned PowerShell Child Process on Windows
Alerts on PowerShell spawning from WmiPrvSE.exe, a possible indicator of WMI-based remote execution.
sigmaWindowsmedium2019-04-03Windows Security 5145 Network Share Access to Sensitive File Extensions
Alerts when Windows users access network-shared files with extensions commonly targeted for credential or data collection.
sigmaWindowsmedium2019-04-03Windows GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Writes (Security 5136/5145)
Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.
sigmaWindowshigh2019-04-03Windows Security 4661 Detects Privileged AD User/Group SID Enumeration via SAM
Identifies SAM_USER/SAM_GROUP access events (4661) aimed at privileged SIDs or names containing 'admin' while ignoring computer accounts.
sigmaWindowshigh2019-04-03Windows Security 5136: Modify AD ACL for DCSync Extended Right via ntSecurityDescriptor
Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.
sigmaWindowshigh2019-04-03Windows Suspicious EXE in User Directory Launched by Microsoft Office Applications
Alert on Office spawning a .exe from C:\users\ (except when the child is Teams.exe).
sigmaWindowshigh2019-04-02Windows Security Logon Event ID 4800: Workstation Lock After Inactivity
Locked Workstation
sigmaWindowsinformational2019-03-26Windows ADSI Schema Cache (.sch) File Creation by Uncommon Process
Alerts on .sch cache file creation in the Windows SchCache directory by uncommon executables.
sigmaWindowsmedium2019-03-24Windows Security Event 5136: Suspicious LDAP attribute display names used
Alerts on Event 5136 containing specific LDAP display names indicative of LDAP-based data exchange.
sigmaWindowshigh2019-03-24Windows ETW Trace Evasion via Clearing/Disabling Logs or Providers
Identifies command-line attempts to clear/disable ETW traces or remove/modify ETW providers on Windows.
sigmaWindowshigh2019-03-22Windows: certutil.exe File Encoding to Base64 Using the -encode Flag
Alerts on Windows certutil.exe executions using -encode to base64-encode a file.
sigmaWindowsmedium2019-02-24Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
sigmaWindowslow2019-02-23