Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows svchost.exe Spawned by Uncommon Parent Process
Alerts when svchost.exe starts with an unusual parent process name on Windows.
sigmaWindowsmedium2017-08-15Windows Security: Account Encryption/Preauth/Delegation Flags Weakened in User Account Changes
Flags Windows Event ID 4738 user account changes that enable weaker encryption or related pre-auth behavior.
sigmaWindowshigh2017-07-30Windows Security: SeEnableDelegationPrivilege Enabled via AD User Right (Event 4704)
Alerts when Event ID 4704 assigns SeEnableDelegationPrivilege, enabling control over other AD user objects.
sigmaWindowshigh2017-07-30Windows Security Events Indicating File Deletion Attempts Using SDelete Extensions
Alerts on Windows security file access events for object names ending in .AAA or .ZZZ, consistent with secure deletion behavior.
sigmaWindowsmedium2017-06-14Windows WCE wceaux.dll File Access via Security Event 4656/4663
Identifies Windows Security event activity involving access to the wceaux.dll library file.
sigmaWindowscritical2017-06-14Windows PsExec Service Execution via PSEXESVC.exe
Detects PsExec service execution by matching the PSEXESVC.exe process on Windows.
sigmaWindowsmedium2017-06-12Windows: PsExec Service File Creation via PSEXESVC.exe Written to Disk
Flags Windows file creation of \PSEXESVC.exe, indicating potential PsExec service deployment for remote execution.
sigmaWindowslow2017-06-12Windows PsExec Service Installation via Service Control Manager (Event ID 7045)
Flags Service Control Manager Event ID 7045 when a PSEXESVC service is installed with ImagePath ending in \PSEXESVC.exe.
sigmaWindowsmedium2017-06-12Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Alerts when RULER-labeled Windows Security events show NTLM auth (4776) plus 4624/4625 logons.
sigmaWindowshigh2017-05-31Windows Registry: DHCP Server Callout DLL and Enable Parameters Installation
Alerts on registry changes enabling and configuring DHCP Server callout DLLs via CalloutDlls and CalloutEnabled.
sigmaWindowshigh2017-05-15Windows ETW: Kernel-General resets registry hive access bits in temp hive paths
Detects ETW EventID 16 when access bits are reset for Temp \SAM or \SECURITY hives.
sigmaWindowshigh2017-05-15Windows DHCP Server Error: Callout DLL Failed to Load
Flags DHCP Server events showing failure to load a configured Callout DLL (Event IDs 1031/1032/1034).
sigmaWindowshigh2017-05-15Windows DHCP Server Loaded Callout DLL via Registry
Flags DHCP Server events where a registry-specified callout DLL is loaded (Event ID 1033), indicating potential persistence or execution.
sigmaWindowshigh2017-05-15Windows Backup Catalog Deleted (Microsoft-Windows-Backup Event ID 524)
Alerts when Windows deletes the backup catalog via Microsoft-Windows-Backup Event ID 524.
sigmaWindowsmedium2017-05-12Windows Error Reporting: MsMpEng.exe Crash with mpengine.dll
Alerts on WER EventID 1001 crashes where MsMpEng.exe and mpengine.dll appear in the event data.
sigmaWindowshigh2017-05-09Windows Application Error: MsMpEng.exe Crash Involving mpengine.dll
Alerts on Windows Application Error EventID 1000 indicating a crash involving MsMpEng.exe and mpengine.dll.
sigmaWindowshigh2017-05-09Windows DNS ServerLevelPluginDll Registry Installation
Detects registry changes setting DNS ServerLevelPluginDll, which can enable malicious DNS plugin DLL loading after restart.
sigmaWindowshigh2017-05-08Windows: Detect dnscmd.exe setting ServerLevelPluginDll to install DNS plugin DLL
Flags dnscmd.exe DNS configuration that sets ServerLevelPluginDll, indicating potential malicious DNS server code injection.
sigmaWindowshigh2017-05-08Windows DNS Server error when loading ServerLevelPlugin DLL fails
Flags Windows DNS Server errors where the ServerLevelPluginDLL plugin DLL fails to load.
sigmaWindowshigh2017-05-08Windows Rundll32 DLL Load via control.exe spawning
Alerts on control.exe spawning rundll32.exe to load Shell32.dll via DLL invocation patterns.
sigmaWindowshigh2017-04-15