Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: Detect renamed PingCastle binary execution via PE metadata and scanner command-line
Flags Windows processes that look like renamed PingCastle executables using PE original file names and PingCastle scanner/healthcheck arguments.
sigmaWindowshigh2024-01-11Windows PingCastle Execution From Suspicious Parent Processes
Alerts on PingCastle (PingCastle.exe) being run with full scan/healthcheck arguments from potentially suspicious parent process locations.
sigmaWindowshigh2024-01-11Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners
Alerts on Windows execution of PingCastle with full healthcheck and AD/security scanner command-line options.
sigmaWindowsmedium2024-01-11Windows .cpl Image Loads from Uncommon Paths Indicating Control Panel Abuse
Alerts on Windows loading of .cpl control panel items from uncommon paths instead of standard system directories.
sigmaWindowshigh2024-01-09Windows WFP 5157: Connection Blocked for EDR Agent Binaries
Flags WFP blocked connections (EventID 5157) when an EDR/security agent binary is the blocked application.
sigmaWindowshigh2024-01-08Windows forfiles.exe Spawned cmd.exe from Non-System Location
Alerts on forfiles.exe running outside system paths and spawning cmd.exe with a forfiles-encoded command pattern.
sigmaWindowshigh2024-01-05Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
Alerts on Windows Filtering Platform policy change events containing "RonPolicy" consistent with NoFilter abuse.
sigmaWindowshigh2024-01-05Windows Process Creation: EDRSilencer Executed
Flags execution of EDRSilencer.exe on Windows based on process image and identifying metadata.
sigmaWindowshigh2024-01-02Windows Process Execution of dotnet-trace.exe Child via '-- collect' Arguments
Alerts on dotnet-trace.exe executions with '-- ' and 'collect' command-line arguments that may proxy child process execution.
sigmaWindowsmedium2024-01-02Windows Registry Persistence via AppCompatFlags Layers REGISTERAPPRESTART
Detects registry persistence settings that include the AppCompat layer "REGISTERAPPRESTART" on Windows.
sigmaWindowsmedium2024-01-01Windows Registry Change to Desktop Wallpaper Policy or Settings
Detects Windows registry updates that enforce or change the desktop wallpaper and restrict user control.
sigmaWindowsmedium2023-12-21Windows reg.exe Changes Desktop Background Policy Values
Alerts when reg.exe is used to modify Windows registry settings that control wallpaper or desktop background behavior.
sigmaWindowsmedium2023-12-21Windows Process Execution of Renamed cloudflared.exe with Tunnel/Run Command Arguments
Alerts on Windows process executions of renamed cloudflared with tunnel run/cleanup command-line arguments or matching SHA-256 hashes.
sigmaWindowshigh2023-12-20Windows Execution of cloudflared for Cloudflare Try/Quick Tunnel Ad-hoc Tunneling
Flags execution of cloudflared on Windows with -url arguments consistent with Cloudflare Quick Tunnel setup.
sigmaWindowsmedium2023-12-20Windows execution of cloudflared.exe from a non-default directory
Alerts on cloudflared.exe executions from unusual paths on Windows, excluding standard Program Files locations.
sigmaWindowsmedium2023-12-20Windows DNS Queries for Cloudflared Tunnel Domains
Alerts on Windows DNS queries for domains ending with common Cloudflared tunnel hostnames.
sigmaWindowsmedium2023-12-20Windows: tar.exe Archive Extraction Using -x Flag
Flags Windows process executions of tar.exe with -x to extract compressed archives.
sigmaWindowslow2023-12-19Windows tar.exe Used to Create Compressed Archives
Flags tar.exe (or bsdtar) command lines using -c/-r/-u to create or update compressed archives on Windows.
sigmaWindowslow2023-12-19Windows Registry: Set LSA NoLMHash to 0 to Enable LM Hash Storage
Flags changes to NoLMHash (DWORD 0) enabling Windows to store LM password hashes.
sigmaWindowshigh2023-12-15Windows Process Creation: Enable LM Hash Storage via Lsa\NoLMHash=0 in Command Line
Flags process command lines that set Lsa\NoLMHash to 0 to enable LM hash storage.
sigmaWindowshigh2023-12-15