Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: Outlook EnableUnsafeClientMailRules Security Setting Enabled
Flags Windows process command lines that reference Outlook’s EnableUnsafeClientMailRules security setting.
sigmaWindowshigh2018-12-27Windows Process Creation: SecurityXploded PasswordDump.exe Execution
Alerts on Windows executions of SecurityXploded PasswordDump.exe based on process metadata and filename.
sigmaWindowscritical2018-12-19Windows Process Creation: Rubeus HackTool Execution Indicators
Flags Windows process executions of Rubeus.exe when command lines include Kerberos attack-related actions.
sigmaWindowscritical2018-12-19Windows Process Creation: Command Line Obfuscation via Escape Characters
Identifies Windows process command lines containing escape-character URL obfuscation patterns.
sigmaWindowsmedium2018-12-11Windows Remote Thread Injection Indicators via Process StartAddress Suffixes
Flags Windows CreateRemoteThread events with StartAddress suffixes 0B80, 0C7C, or 0C88.
sigmaWindowshigh2018-11-30Windows: Suspicious Executable Downloads Missing File Metadata Fields
Alerts when a process launches from Downloads with missing/placeholder file metadata (Description, FileVersion, Product, or Company).
sigmaWindowsmedium2018-11-22Windows PowerShell Base64-encoded shellcode in ScriptBlockText
Flags PowerShell script blocks containing Base64 strings matching known shellcode markers.
sigmaWindowshigh2018-11-17Windows: Potential Kerberoasting SPN Enumeration via setspn.exe
Detects Windows setspn.exe runs with SPN query command-line parameters that may indicate Kerberoasting preparation.
sigmaWindowsmedium2018-11-14Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
sigmaWindowshigh2018-10-30Windows: Local user account creation via net.exe or net1.exe
Alerts on net.exe/net1.exe launching with "user" and "add" to create local accounts on Windows.
sigmaWindowsmedium2018-10-30Suspicious XOR-Encoded PowerShell Command Line (Windows Process Creation)
Flags PowerShell (powershell.exe/pwsh) process executions with command-line indicators consistent with XOR/obfuscated scripting.
sigmaWindowsmedium2018-09-05Windows PowerShell Suspicious Encoded Command-Line Execution
Alerts on PowerShell launched with encoded-command switches and embedded encoded content patterns in the command line.
sigmaWindowshigh2018-09-03Windows Process in Suspicious Folder Initiating Network Connections to File Sharing Domains
Alerts on outbound connections to file sharing domains from Windows executables running out of suspicious temp/recycle/task paths.
sigmaWindowshigh2018-08-30Windows LSASS process access blocked by Attack Surface Reduction (Windows Defender event 1121)
Alerts on windefend EventID 1121 for blocked access to lsass.exe, excluding common benign process callers.
sigmaWindowshigh2018-08-26Windows Registry Run Key Set to Executable in Suspicious Folder
Flags new Windows Run key values pointing to executables in suspicious folders, excluding known update/Spotify patterns.
sigmaWindowshigh2018-08-25Windows Process Creation: PowerShell Command Execution Hidden in DLL Invocation
Flags DLL-invoking Windows binaries whose command lines include PowerShell execution strings.
sigmaWindowshigh2018-08-25Windows: .NET Reflection Attempt to Disable AMSI via amsiInitFailed
Alerts on Windows command lines referencing amsiInitFailed and .NET reflection patterns to disable AMSI scanning.
sigmaWindowshigh2018-08-17PowerShell NTFS Alternate Data Stream Writes via set-content/add-content
Alerts on PowerShell Set/Add-Content operations that specify -Stream, indicating potential NTFS Alternate Data Stream writes.
sigmaWindowshigh2018-07-24Windows: SafetyKatz LSASS dump default file indicator (Temp\debug.bin)
Flags Windows file events with a target path ending in \Temp\debug.bin, consistent with SafetyKatz LSASS dump output.
sigmaWindowshigh2018-07-24Windows Registry Explorer Run Key Persistence Pointing to Suspicious Paths
Alerts on writes to the Explorer Run policy registry key with details pointing to suspicious filesystem paths.
sigmaWindowshigh2018-07-18