Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Network Connections to Cloudflared Tunnel Domains
Alerts when a Windows process initiates outbound connections to Cloudflared tunnel domain hostnames.
sigmaWindowsmedium2024-05-27Windows: File Creation by mysqld.exe With Script/Executable Extensions
Alerts on file creation by mysqld.exe producing .bat/.exe/.ps1/.vbs and other executable or script file types on Windows.
sigmaWindowshigh2024-05-27Suspicious Child Process of KeyScrambler.exe on Windows
Alerts on KeyScrambler.exe launching cmd.exe, PowerShell, script hosts, regsvr32, or rundll32 as child processes.
sigmaWindowsmedium2024-05-13PowerShell Start-NetEventSession Script Block Execution Indicating Potential Network Capture (Windows)
Alerts when PowerShell ScriptBlocks reference Start-NetEventSession, indicating potential network packet or event capture.
sigmaWindowsmedium2024-05-12Windows Registry: UAC PromptOnSecureDesktop Disabled
Detects setting UAC PromptOnSecureDesktop to 0 via Windows registry policy, disabling secure desktop for UAC prompts.
sigmaWindowsmedium2024-05-10Windows Registry: UAC notification disabled via UACDisableNotify set to DWORD 0x00000001
Alerts on registry changes that disable UAC notifications by setting UACDisableNotify to 0x00000001 on Windows.
sigmaWindowsmedium2024-05-10Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
sigmaWindowshigh2024-05-10Windows Process: File Recovery from Backup via wbadmin.exe
Flags wbadmin.exe executions that perform file recovery from backups based on recoveryTarget and itemtype:File arguments.
sigmaWindowsmedium2024-05-10Windows Process Creation: wbadmin.exe Triggered for Backup of Sensitive Registry and NTDS Files
Alerts on wbadmin.exe backup commands that reference SAM/SECURITY/SYSTEM hives or NTDS.DIT.
sigmaWindowshigh2024-05-10Windows Firewall Allow Rule Added via WmiPrvSE.exe
Flags Windows firewall allow-rule additions where WmiPrvSE.exe is the modifying application.
sigmaWindowsmedium2024-05-10Windows: Alert on Outbound Connections Initiated by dialer.exe (Microsoft Phone Dialer)
Alerts on outbound connections started by Windows dialer.exe, excluding common local and reserved IP ranges.
sigmaWindowshigh2024-04-26Windows Process Creation: SoftPerfect netscan.exe Network Scanner Execution
Alerts on execution of SoftPerfect Network Scanner (netscan.exe), a potential network reconnaissance tool.
sigmaWindowsmedium2024-04-25Windows RegAsm.exe Initiates Network Connection to Public IP
Alerts on RegAsm.exe initiating outbound connections to public (non-local/private) IP addresses.
sigmaWindowsmedium2024-04-25Windows DLL side-loading: KeyScramblerIE.DLL loaded by KeyScrambler.exe
Alerts on KeyScrambler.exe loading KeyScramblerIE.dll, a common DLL side-loading pattern that may indicate malicious library execution.
sigmaWindowshigh2024-04-15Windows Registry: MaxMpxCt Value Changed (LanmanServer Parameters)
Monitors Windows registry updates to MaxMpxCt under LanmanServer parameters, impacting SMB connection request handling.
sigmaWindowslow2024-03-19Windows Execution of Renamed NirCmd.exe (nircmd.exe/nircmdc.exe) via PE OriginalFileName
Alerts when a process uses NirCmd.exe PE metadata while the executable name is renamed to nircmd.exe or nircmdc.exe.
sigmaWindowshigh2024-03-11Windows TeamViewer Remote Session Process Command Line Start
Flags TeamViewer_Desktop.exe being launched by TeamViewer_Service.exe with the expected IPCport and module parameters on Windows.
sigmaWindowslow2024-03-11Windows File Creation of CrackMapExec-Related Temp Scripts and Output Files
Flags Windows file creation in C:\Windows\Temp\ with filenames and patterns associated with CrackMapExec artifacts.
sigmaWindowshigh2024-03-11Windows Kerberos KDC Key Distribution Failure: No Suitable Encryption Key or Unsupported EType
Flags KDC TGS generation failures where no suitable encryption key intersects or the requested encryption type is unsupported.
sigmaWindowslow2024-03-07Windows AD CS Denied Certificate Enrollment Requests (Event ID 53)
Alerts on CA-side denied certificate enrollment attempts in Windows via Microsoft-Windows-CertificationAuthority Event ID 53.
sigmaWindowslow2024-03-07