Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Suspicious PowerShell WebClient Downloads via PoshModule
Alerts on PowerShell module activity referencing System.Net.WebClient with DownloadFile/DownloadString calls to fetch remote content.
sigmaWindowsmedium2017-03-05Windows PowerShell Execution via EngineVersion/HostVersion Mismatch in Command Start Telemetry
Detects PowerShell execution attempts that match a specific executable EngineVersion/HostVersion mismatch pattern on Windows.
sigmaWindowshigh2017-03-05PowerShell Net.WebClient DownloadFile/DownloadString Usage (Classic)
Flags PowerShell Classic commands using Net.WebClient to download content via DownloadFile or DownloadString.
sigmaWindowslow2017-03-05Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Flags Service Control Manager service creation with ImagePath names tied to credential dumping tools (Event ID 7045).
sigmaWindowshigh2017-03-05Windows Security EID 4697 Service Execution of Credential Dumping Tools
Alerts on Event ID 4697 service execution paths containing common credential dumping tool names on Windows.
sigmaWindowshigh2017-03-05Windows: Detects Access to ADMIN$ Network Share (Event 5140)
Alerts on Windows Security event 5140 entries where an access request targets the ADMIN$ share.
sigmaWindowslow2017-03-04Windows LSASS Remote Thread Creation Indicative of Password Dumping
Flags Windows remote thread creation targeting lsass.exe, a common pattern in password dumping activity.
sigmaWindowshigh2017-02-19Windows Security: Suspicious Failed Logons Using Uncommon Status/Substatus Codes
Alerts on Windows failed logons (4625/4776) with specific restricted-status codes indicating potential account tampering or access probing.
sigmaWindowsmedium2017-02-19Windows Security Event 4794 Password Change for DSRM Account
Flags potential changes to the DSRM administrator password on Windows domain controllers using Security EventID 4794.
sigmaWindowshigh2017-02-19Windows Security Events: SID History Added to Active Directory Object
Flags Windows Security events indicating Active Directory SIDHistory changes that can grant additional privileges.
sigmaWindowsmedium2017-02-19Windows Application Logs: Match Antivirus Signature and Malware Keyword Hits
Alerts on Windows application log lines containing known AV signatures and malware keywords, excluding some anti-ransomware/keygen/crack terms.
sigmaWindowshigh2017-02-19Windows Driver Load from Temporary Directory Paths
Detects Windows driver loads whose ImageLoaded path contains the temporary directory (\Temp\).
sigmaWindowshigh2017-02-12Windows Security: Detect LSASS handle access for SAM_DOMAIN (0x705)
Flags handle opens to lsass.exe with access mask 0x705 targeting SAM_DOMAIN, indicative of credential dumping.
sigmaWindowshigh2017-02-12Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)
Alerts on Windows Security failures for Kerberos TGT-related operations using specific Kerberos event IDs and status codes.
sigmaWindowshigh2017-02-10Windows Kerberos Service Tickets Requesting RC4 Encryption (EventID 4769)
Flags Windows Kerberos service ticket requests using RC4 encryption while excluding '$' machine/service accounts.
sigmaWindowsmedium2017-02-06Windows Event Logs: Mimikatz Keyword Indicators
Detects Mimikatz-related keywords in Windows event logs while filtering Sysmon EventID 15 to limit noise.
sigmaWindowshigh2017-01-10Windows Event Log Cleared (Microsoft-Windows-Eventlog EventID 104)
Alerts when Windows event logs are cleared, based on Microsoft-Windows-Eventlog Event ID 104 from System telemetry.
sigmaWindowsmedium2017-01-10Windows Security and Eventlog Cleared via Event IDs 517 or 1102
Flags Windows event log clearing using Security Event ID 517 and Microsoft-Windows-Eventlog Event ID 1102.
sigmaWindowshigh2017-01-10Windows Webshell Recon Command-Line Keywords via Web Server Processes
Flags Windows process chains where web server parents spawn reconnaissance- and execution-related command lines indicative of webshell activity.
sigmaWindowshigh2017-01-01Windows WerFault Access to lsass.exe Indicative of Credential Dumping Attempts
Alert on WerFault.exe gaining broad access to lsass.exe, consistent with credential dumping attempts.
sigmaWindowshigh2012-06-27