Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows mshta.exe Execution Using Non-HTA File Extensions
Alerts on mshta.exe launched with command-line indicators for suspicious non-HTA file types and VBScript.
sigmaWindowshigh2019-02-22Windows: RDP Session Startup Folder Backdoor via tsclient Share Targeting Startup Path
Flags mstsc.exe activity writing to the Windows Startup folder, indicating potential RDP session backdoor placement.
sigmaWindowshigh2019-02-21Windows svchost RDP via Reverse SSH Loopback Tunnel to 127.0.0.0/8:3389
Flags svchost.exe opening RDP (TCP 3389) connections to loopback, consistent with tunneled reverse access behavior.
sigmaWindowshigh2019-02-16Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Flags Windows EventID 5156 where svchost RDP (3389) traffic targets loopback addresses, suggesting tunneled local RDP usage.
sigmaWindowshigh2019-02-16Windows: Alert on suspicious parent process spawning csc.exe
Flags csc.exe execution when spawned by script/document hosts or PowerShell using encoded content, excluding common benign parent contexts.
sigmaWindowshigh2019-02-11Windows PowerShell Script Block Matches Common Reflection and Injection Keywords
Alerts on PowerShell script block text containing reflection, dynamic assembly loading, and injection-related keywords.
sigmaWindowsmedium2019-02-11Windows Process Creation: Suspicious calc.exe Command-Line Usage Outside System Locations
Alerts on suspicious calc.exe launches via command-line parameters or execution from non-standard Windows directories.
sigmaWindowshigh2019-02-09Windows bcdedit.exe Tampering for MBR/Boot Persistence (Delete, Import, SafeBoot, Network)
Alerts on bcdedit.exe executions with command-line options consistent with boot configuration tampering.
sigmaWindowsmedium2019-02-07Windows Process Creation: Suspicious GUP.exe Execution from Non-Notepad++ Directories
Alerts on GUP.exe executions from unexpected directories on Windows, excluding known Notepad++ updater paths.
sigmaWindowshigh2019-02-06Windows Security Event 4616 for System Time Changes by Non-Service Accounts
Flags Windows Event 4616 system time changes when made by processes outside svchost.exe and common virtualization agents.
sigmaWindowslow2019-02-05Windows Remote Thread Creation via CACTUSTORCH Using Script/Office/Rundll Host Images
Alerts on SysWOW64 remote thread creation initiated by script host or Office binaries consistent with CACTUSTORCH behavior.
sigmaWindowshigh2019-02-01Windows netsh.exe Used to Create RDP (3389) Port Forwarding
Flags netsh.exe executions that appear to set up RDP (3389) port forwarding.
sigmaWindowshigh2019-01-29Windows netsh.EXE Adds Portproxy v4-to-v4 Forwarding Rule
Flags netsh.exe command lines that add portproxy v4-to-v4 forwarding rules on Windows.
sigmaWindowsmedium2019-01-29Windows Firewall Rule Added via netsh.exe
Flags netsh.exe executions that add Windows firewall rules, indicating potential attacker-controlled network access changes.
sigmaWindowsmedium2019-01-29Windows RDP Logon Using Localhost IP Address
Alerts on successful Windows logons (EventID 4624, LogonType 10) originating from localhost IPs.
sigmaWindowshigh2019-01-28Windows Registry: New Security Support Provider (SSP) added to LSA configuration
Alerts when a new SSP is added to LSA Security Packages in the Windows registry, excluding msiexec-driven changes.
sigmaWindowshigh2019-01-18Windows Script Execution from User-Accessible Paths via WScript, CScript, or MSHTA
Alerts when WScript/CScript/MSHTA launches scripts or HTAs referenced from user and temp directories.
sigmaWindowsmedium2019-01-16Windows Process Creation Attempt Using wmic.exe process call create
Alerts on Windows process creation attempts invoking wmic.exe with “process call create”, a common pattern for WMI-based execution.
sigmaWindowsmedium2019-01-16Windows Suspicious Child Processes Spawned by Web Server Executables
Alerts when web server processes (e.g., nginx/httpd/caddy/php/tomcat) spawn suspicious Windows command/scripting executables.
sigmaWindowshigh2019-01-16Windows Process Execution From Uncommon or Sensitive Directories
Alerts on process executions from uncommon/sensitive Windows directories, excluding specific IBM and Citrix updater paths.
sigmaWindowshigh2019-01-16