Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Shim Database Persistence via sdbinst.exe with .sdb Payload
Alerts when sdbinst.exe runs and references a .sdb shim database, indicating potential shim-based persistence.
sigmaWindowsmedium2019-01-16Windows schtasks.exe Scheduled Task Creation by Non-Microsoft Office Integration
Alerts on schtasks.exe /create executions indicating scheduled task creation, with exclusions for Office integrator-related cases.
sigmaWindowslow2019-01-16Windows Process Creation: Suspicious rundll32 Command-Line Invocations of Common DLL Entry Points
Detects rundll32 runs whose command lines reference specific DLL exports often abused for LOLBIN execution.
sigmaWindowsmedium2019-01-16Windows Process Execution from Unusual System Locations
Alerts on Windows process launches where the executable path is in or contains unusual directories like RECYCLER or SystemVolumeInformation.
sigmaWindowsmedium2019-01-16Windows Suspicious rasdial.exe Process Execution
Flags Windows process executions of rasdial.exe by matching process image names ending with rasdial.exe.
sigmaWindowsmedium2019-01-16Windows Process Creation: Suspicious PowerShell Argument Obfuscation via Truncated Substrings
Alerts on PowerShell executions where the command line contains suspicious truncated parameter substrings (e.g., windowstyle, NoProfile, encoded/exec policy, bypass).
sigmaWindowshigh2019-01-16PowerShell Spawned by wscript.exe or cscript.exe on Windows
Flags PowerShell launched by Windows script engines (wscript/cscript), excluding specific Health Service State activity.
sigmaWindowsmedium2019-01-16Windows PowerShell execution with download-related command line patterns
Alerts when PowerShell is started with command-line fragments indicative of downloading remote content.
sigmaWindowsmedium2019-01-16Windows Process Creation: PowerShell Command Lines with Hidden Base64-Encoded Keywords
Alerts on PowerShell launching with 'hidden' and embedded base64-like strings in the command line.
sigmaWindowshigh2019-01-16Windows: Execution of ntdsutil.exe for NTDS database operations
Flags execution of ntdsutil.exe, a utility that can be used to manipulate the NTDS database (NTDS.DIT).
sigmaWindowsmedium2019-01-16Windows Process Reconnaissance via net.exe Group/Account Queries
Alerts on Windows net.exe commands querying groups and accounts via domain/local group and /do-related flags.
sigmaWindowsmedium2019-01-16Windows Process Creation: Suspicious Children Spawned by mshta.exe
Flags mshta.exe spawning command, script, or utility processes commonly abused for executing malicious HTA payloads.
sigmaWindowshigh2019-01-16Windows Java Process Started with Remote Debugging Enabled for Non-Localhost Connections
Identifies Java processes started with JDWP dt_socket remote debugging on a non-localhost address.
sigmaWindowsmedium2019-01-16Windows Cmdkey.EXE Cached Credential Reconnaissance
Alerts on cmdkey.exe running with -l to enumerate cached credentials on a Windows host.
sigmaWindowshigh2019-01-16Windows cmd.exe Command Line with URL and %AppData% Indicators
Alerts on cmd.exe executions whose command line includes a URL pattern (http/https) and %AppData%.
sigmaWindowsmedium2019-01-16Windows WMI Event Subscription Creation (Sysmon Event 19/20/21)
Flags Sysmon-reported WMI event subscription filter/consumer activity (Event IDs 19–21) indicative of persistence.
sigmaWindowsmedium2019-01-12Windows Registry Persistence via UserInitMprLogonScript Value
Detects registry value name containing "UserInitMprLogonScript", which may indicate logon-script persistence setup.
sigmaWindowsmedium2019-01-12Windows userinit.exe Spawns Uncommon Child Processes
Alerts when userinit.exe starts an unexpected child process during logon, suggesting potential persistence via modified logon behavior.
sigmaWindowshigh2019-01-12Windows Command Line Logon Script Persistence via UserInitMprLogonScript
Alerts when a Windows process command line references UserInitMprLogonScript, a potential logon-script persistence indicator.
sigmaWindowshigh2019-01-12PowerShell Executed From AppData on Windows (Command Line Indicators)
Flags PowerShell command lines that include AppData paths (Local/Roaming), indicating possible user-profile script execution.
sigmaWindowsmedium2019-01-09