Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry Events: CMSTP Execution via cmmgr32.exe TargetObject
Flags registry events referencing \cmmgr32.exe, consistent with CMSTP-related execution behavior on Windows.
sigmaWindowshigh2018-07-16Windows CMSTP Process Spawning Child Process
Alerts on child processes spawned by Windows cmstp.exe, a common signal for CMSTP abuse.
sigmaWindowshigh2018-07-16Windows Process Access to cmlua.dll by CMSTP Connection Manager Profile Installer
Alerts on Windows process access events whose call trace includes cmlua.dll, indicating potential CMSTP-related execution.
sigmaWindowshigh2018-07-16Windows PowerShell Remote Thread Creation Into Uncommon Target Processes
Alerts on PowerShell creating remote threads in rundll32.exe or regsvr32.exe on Windows.
sigmaWindowsmedium2018-06-25Windows Sysprep Execution Targeting AppData Directory
Alerts when sysprep.exe runs with an AppData directory present in the command line on Windows.
sigmaWindowsmedium2018-06-22Windows NTLM authentication events (Event ID 8002)
Alerts on Windows NTLM authentication occurrences based on Event ID 8002 from Microsoft-Windows-NTLM/Operational.
sigmaWindowslow2018-06-08Windows Process Creation: svchost.exe Spawns mshta.exe (LethalHTA)
Alerts on Windows instances where svchost.exe spawns mshta.exe, indicating potential LethalHTA execution.
sigmaWindowshigh2018-06-07Windows NTFS Alternate Data Stream Creation with Non-Default Imphash
Alerts on NTFS ADS creation where the stream hash includes a non-null IMPHASH marker, consistent with hidden executables.
sigmaWindowsmedium2018-06-03Windows Security: Detects suspicious DC Sync via Event 4662 access to replication rights
Flags Windows EventID 4662 directory replication permission events matching DC Sync–related GUIDs and properties while excluding common service accounts.
sigmaWindowshigh2018-06-03Windows Registry Persistence via Image File Execution Options GlobalFlag and SilentProcessExit
Flags registry changes to IFEO GlobalFlag and SilentProcessExit keys that can enable stealthy persistence or process redirection.
sigmaWindowshigh2018-04-11Windows Process Creation: Access to Domain Group Policy in SYSVOL
Flags Windows processes that reference SYSVOL \policies paths in their command line.
sigmaWindowsmedium2018-04-09Windows File Events: Known Offensive PowerShell Script File Creation
Alerts on creation of known offensive PowerShell/PowerShell module filenames on Windows.
sigmaWindowshigh2018-04-07Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Alerts when mshta/PowerShell and similar script hosts spawn tasks, download/transfer, or utility tools on Windows.
sigmaWindowshigh2018-04-06Windows: Suspicious Process Spawning from Microsoft Office Applications
Alerts when Office apps spawn common execution tools or scripts from typical attacker staging paths on Windows.
sigmaWindowshigh2018-04-06Windows Ping Hex IP Usage via Command Line
Flags ping.exe executions that pass a hex-encoded IPv4 address (0x????????) in the command line on Windows.
sigmaWindowshigh2018-03-23Windows Service Control Manager flags smbexec.py-style service installation via suspicious ImagePath
Flags suspicious Windows service installations matching a specific service name and BAT/delete command patterns in Event 7045.
sigmaWindowshigh2018-03-20Windows Security: Registry NetNTLM Downgrade Configuration Changes
Alerts on Windows registry changes that weaken NetNTLM/NTLM security settings via LSA compatibility and restriction values.
sigmaWindowshigh2018-03-20Windows Process Creation: taskmgr.exe launched in LOCAL_SYSTEM context
Flags taskmgr.exe process creation when initiated under a LOCAL_SYSTEM-equivalent user context string.
sigmaWindowshigh2018-03-18Windows Suspicious RDP Session Redirect via tscon.exe /dest:rdp-tcp#
Alerts on Windows process executions using tscon.exe-style RDP redirection to an "rdp-tcp#" destination.
sigmaWindowshigh2018-03-17Windows: Detect tscon.exe launched under SYSTEM context
Alerts on tscon.exe starting under a SYSTEM-associated user context based on Windows process creation logs.
sigmaWindowshigh2018-03-17