Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Security: AD user/computer backdoor via msDS-AllowedToDelegateTo and delegation attributes
Alerts on AD delegation-related attribute changes that may create credentialless account control paths.
sigmaWindowshigh2017-04-13PowerShell Credential Prompt via PromptForCredential
Flags PowerShell scripts that reference "PromptForCredential", indicating credential prompt behavior in Script Block Logging.
sigmaWindowshigh2017-04-09PowerShell downgrade indicators via EngineVersion=2. and HostVersion !=2. (Windows)
Detects PowerShell version mismatches that may indicate a downgrade attempt using EngineVersion vs HostVersion telemetry.
sigmaWindowsmedium2017-03-22Windows Registry UAC Bypass via Event Viewer Command Key (mscfile shell open command)
Alerts on registry changes to the mscfile shell open command key consistent with an Event Viewer UAC bypass technique.
sigmaWindowshigh2017-03-19Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
Alerts when eventvwr.exe spawns unusual child processes in Windows process creation logs.
sigmaWindowshigh2017-03-19Windows Network Connections to Uncommon Ports (8080, 8888)
Flags Windows-initiated connections to ports 8080/8888 excluding private/local IPs and Program Files binaries.
sigmaWindowsmedium2017-03-19Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
sigmaWindowshigh2017-03-19Windows network connection from process running in suspicious or uncommon file paths
Alerts on Windows network connections initiated by processes executing from suspicious or uncommon directories.
sigmaWindowshigh2017-03-19Windows UAC Bypass Indicator via sdclt Registry Key Manipulation
Alerts on registry set activity consistent with sdclt-related UAC bypass key manipulation.
sigmaWindowshigh2017-03-17Windows Security: Local Administrators Group Membership Change (Event 4732)
Flags Windows Event 4732 where a user is added to the local Administrators group.
sigmaWindowsmedium2017-03-14Windows PowerShell ScriptBlock with Encoded, Hidden, or Noninteractive Execution Parameters
Alerts on PowerShell ScriptBlockText containing encoded command, hidden window, or noninteractive execution parameters.
sigmaWindowshigh2017-03-12Suspicious PowerShell Module Execution Using Encoded, Hidden, or Noninteractive Context (Windows)
Alerts on PowerShell module executions using encoded commands, hidden windows, or noninteractive flags to evade visibility and interaction.
sigmaWindowshigh2017-03-12Windows BITSAdmin File Download via bitsadmin.exe with Transfer/Addfile Arguments
Flags bitsadmin.exe being started with parameters consistent with transferring/downloading files from an http URL.
sigmaWindowsmedium2017-03-09Windows Security: Detects SAM User/Group Access During Domain Recon (Event ID 4661)
Alerts on Event ID 4661 accesses to SAM user/group objects for domain Administrator and Domain Admins.
sigmaWindowshigh2017-03-07Suspicious PowerShell Script Block Invocations Using Encoded/Hidden Execution and Persistence Commands
Flags PowerShell script blocks using hidden/non-interactive execution, encoded/decode patterns, iex execution, web downloads, or run key modifications.
sigmaWindowshigh2017-03-05PowerShell ScriptBlock WebClient Download Calls
Alert on PowerShell ScriptBlock text that uses System.Net.WebClient to download files or strings from the Internet.
sigmaWindowsmedium2017-03-05Windows PowerShell Script Block Logging: PSAttack marker string
Alerts when PowerShell script blocks contain the "PS ATTACK!!!" marker on Windows.
sigmaWindowshigh2017-03-05Windows PowerShell Script Block Contains Exploitation Framework and Credential Theft Keywords
Alerts on PowerShell script block text containing known exploitation, token, and memory-related keywords.
sigmaWindowsmedium2017-03-05Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Alerts when PowerShell ScriptBlock text includes strings matching known malicious commandlets from common exploitation toolsets.
sigmaWindowshigh2017-03-05Suspicious PowerShell Module Usage with Hidden/Encoded Execution Parameters on Windows
Flags hidden or encoded PowerShell invocations that decode/execute code or download-and-execute patterns, while filtering a Chocolatey installer snippet.
sigmaWindowshigh2017-03-05