Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry Image File Execution Options Debugger Backdoor (sethc.exe/utilman.exe/osk.exe)
Alerts on registry Debugger hijacks for Windows login/accessibility binaries using Image File Execution Options.
sigmaWindowscritical2018-03-15Windows Backdoor Execution via Sticky Keys and Login-Screen Accessibility Tools
Flags winlogon.exe spawning command/script tools referencing login-screen accessibility binaries (sethc.exe, utilman.exe, osk.exe, etc.).
sigmaWindowscritical2018-03-15Windows Process Creation with taskmgr.exe as Parent Process
Flags process creation where taskmgr.exe is the parent, excluding a few known benign child process images.
sigmaWindowslow2018-03-13Windows WMI Script Event Consumer Execution via scrcons.exe
Flags scrcons.exe starting under svchost.exe, indicating WMI script event consumer execution that can support persistence.
sigmaWindowsmedium2018-03-07Windows WMI Persistence via wbemcons.dll Loaded by WmiPrvSE.exe
Identifies WmiPrvSE.exe loading wbemcons.dll, a behavior consistent with WMI command line event consumer persistence on Windows.
sigmaWindowshigh2018-03-07Windows WMI Persistence: Script Event Consumer File Writes (scrcons.exe)
Flags file writes performed by scrcons.exe, indicating potential WMI script event consumer persistence activity.
sigmaWindowshigh2018-03-07Windows Scheduled Task Creation via PowerShell Using schtasks.exe with ONLOGON/DAILY/ONIDLE/HOURLY
Flags PowerShell-launched schtasks.exe /Create commands matching default PowerSploit/Empire scheduled task persistence behavior.
sigmaWindowshigh2018-03-06Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Flags successful Windows NewCredentials (LogonType 9) logons using seclogo with Negotiate, consistent with Overpass-the-Hash behavior.
sigmaWindowshigh2018-02-12Windows File Creation: QuarksPwDump Credential Dump (.dmp) in Temp\SAM-*
Flags creation of QuarksPwDump .dmp dump files in Temp with a SAM-* filename pattern.
sigmaWindowscritical2018-02-10Windows msiexec Process Creation With Web URL Parameters
Alerts when msiexec is launched with command-line web URL indicators in its parameters.
sigmaWindowsmedium2018-02-09Windows System Binary Execution From Unusual Location (Process Creation)
Alerts when common Windows system binaries run from an uncommon directory rather than standard system locations.
sigmaWindowshigh2017-11-27Windows Security Event 4719 Audit Policy Changes indicate Windows auditing disabled
Flags Windows Event Auditing disabled indicators from Security Event ID 4719 with removed success/failure audit policy.
sigmaWindowslow2017-11-19Windows File Events: java.exe in AppData\Roaming\Oracle\bin Path with .exe and .vbs Artifacts
Alerts on Windows file events for suspicious java*.exe placement in AppData\Roaming\Oracle\bin and .vbs files containing "Retrive".
sigmaWindowshigh2017-11-10Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Flags USB device plug/unplug related Driver Frameworks User-Mode events using Windows event IDs 2003, 2100, and 2102.
sigmaWindowslow2017-11-09Windows Named Pipe Creation Alert for Known Malicious Pipe Names
Alert on Windows named pipe creations where the PipeName matches known malware-associated pipe identifiers.
sigmaWindowscritical2017-11-06Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Alerts on remote logons to admin-named accounts in Windows Security logs (4624, LogonType 10, Negotiate).
sigmaWindowslow2017-10-29Windows Registry Key Created: Sysinternals EULA Acceptance
Flags registry writes indicating Sysinternals EULA acceptance via a TargetObject ending with \EulaAccepted.
sigmaWindowslow2017-08-28Windows: Command-line execution using Sysinternals -accepteula flag
Alerts on Windows processes launched with the -accepteula flag, often associated with Sysinternals tool execution.
sigmaWindowslow2017-08-28Windows WMI Persistence via Event Filter/Consumer Bindings and Filter Registration
Flags likely WMI-based persistence by spotting event filter/consumer bindings and WMI filter registrations tied to script/command-line consumers.
sigmaWindowsmedium2017-08-22Windows WMI Persistence via Security Event 4662 on WMI subscription namespace
Alerts on Security Event 4662 indicating access to WMI Namespace objects with "subscription" in the name.
sigmaWindowsmedium2017-08-22