Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry: SentinelOne Scan Context Menu Command Tampering by Non-SentinelOne Process
Alerts on registry modifications to SentinelOne scan context menu command entries not matching SentinelOne’s expected binary.
sigmaWindowsmedium2024-03-06Windows Utility Loads Unsigned DLL (ImageLoad)
Flags DLL loads by InstallUtil/RegAsm/RegSvcs/regsvr32/rundll32 when the loaded DLL is unsigned or untrusted.
sigmaWindowsmedium2024-02-28Windows ScreenConnect Service Web Shell Execution via cmd.exe or csc.exe
Alert on ScreenConnect.Service.exe spawning cmd.exe or csc.exe, consistent with potential web shell execution on Windows.
sigmaWindowshigh2024-02-26Windows DNS Queries to update.onelaunch.com by OneLaunch.exe
Flags DNS requests to update.onelaunch.com from OneLaunch.exe on Windows.
sigmaWindowslow2024-02-26Windows Suspicious Wget.exe Downloads From IP to Common Staging Paths
Flags wget.exe on Windows downloading from an IP over HTTP and saving to common staging/user directories.
sigmaWindowshigh2024-02-23Windows: User Added to Highly Privileged Local/Directory Groups via net.exe or Add-LocalGroupMember
Flags net.exe or PowerShell commands adding users to privileged groups like Group Policy Creator Owners or Schema Admins.
sigmaWindowshigh2024-02-23Windows SimpleService Execution via Remote Access Tool Wrapper Paths
Flags Windows processes running SimpleService.exe from remote access tool wrapper directories.
sigmaWindowsmedium2024-02-23Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
sigmaWindowshigh2024-02-23Windows Module Usage Enumeration via tasklist.exe -m rdpcorets.dll
Flags tasklist.exe module enumeration (-m) targeting rdpcorets.dll to identify the owning process.
sigmaWindowsmedium2024-02-12Windows sc.exe Service Query for termservice Enumeration
Alerts on sc.exe service querying that references termservice on Windows.
sigmaWindowslow2024-02-12Windows: AnyDesk Execution Using Revoked Certificate Versions
Detects AnyDesk.exe execution on Windows when the file version matches known revoked-certificate releases (excluding uninstall/remove).
sigmaWindowsmedium2024-02-08Windows iexpress.exe Creates Self-Extracting Binaries Using SED Files From Suspicious Paths
Flags suspicious use of Windows iexpress.exe to create self-extracting packages via SED directives from uncommon/temp paths.
sigmaWindowshigh2024-02-05Windows: Alerts on Creation of .sed Self-Extraction Directive File
Flags creation of newly created .sed directive files on Windows, which can be used for self-extracting package abuse.
sigmaWindowsmedium2024-02-05Windows Self Extraction Directive (.sed) File Created in Suspicious Paths
Alerts on .sed directive file creation under ProgramData/Temp/Tasks paths on Windows, consistent with iExpress-based packaging abuse.
sigmaWindowsmedium2024-02-05Windows WMI Disk and Volume Discovery via WMIC.exe
Flags WMIC.exe process executions that query Win32 logical disk and volume listing details.
sigmaWindowsmedium2024-02-02Windows SharpMove (.NET) Execution via SharpMove.exe and Action Command-Line Flags
Alerts on SharpMove.exe process execution with command-line actions for DCOM, WMI VBS, and task scheduler.
sigmaWindowshigh2024-01-29Windows EDRSilencer Execution via Filtering Platform FilterName Change
Detects Filtering Platform custom outbound filter additions associated with potential EDRSilencer execution on Windows.
sigmaWindowshigh2024-01-29Windows Process Creation: SOAPHound Execution via AD Data Collection Command-Line Arguments
Flags SOAPHound execution on Windows by detecting command-line arguments used for Active Directory data collection.
sigmaWindowshigh2024-01-26Uncommon ADWS (Port 9389) Connections from Non-Standard Windows Binaries
Alerts on unexpected process-to-ADWS (TCP/9389) connections on Windows to highlight potential directory discovery.
sigmaWindowsmedium2024-01-26Windows Code Page Change via mode.com Selecting Russian Code Pages
Alerts when mode.com is used to set console code pages to Russian values (1251 or 866).
sigmaWindowsmedium2024-01-17