Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry: HVCI disallowed image list modified (HVCIDisallowedImages)
Alerts when Windows HVCI disallowed images registry value is modified, indicating potential driver load policy tampering.
sigmaWindowshigh2023-12-05Windows Process Creation: whoami.exe Executed With /all for Full Identity Enumeration
Detects Windows executions of whoami.exe using the /all flag to enumerate full identity details.
sigmaWindowsmedium2023-12-04Windows process command line matches WinPwn tool execution keywords
Alerts on Windows process executions with command-line keywords associated with WinPwn (WinPwn.exe/ps1/offline mode).
sigmaWindowshigh2023-12-04Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.
sigmaWindowshigh2023-12-04Windows Registry: Netsh Helper DLL value added under SOFTWARE\Microsoft\NetSh
Alerts on Windows registry writes under SOFTWARE\Microsoft\NetSh that add .dll helper entries.
sigmaWindowsmedium2023-11-28Windows: Netsh helper DLL registration via suspicious registry paths
Flags Netsh helper DLL registration when the DLL path is found in suspicious user/temp-like registry details on Windows.
sigmaWindowshigh2023-11-28Windows ImageLoad: Uncommon Process Loads RstrtMgr.dll (Restart Manager)
Alerts on non-standard processes loading RstrtMgr.dll using Windows image load telemetry.
sigmaWindowslow2023-11-28Windows Image Load of RstrtMgr.dll by Suspicious Path or User Content
Alerts on RstrtMgr.dll loading from suspicious path contexts using Windows image load telemetry.
sigmaWindowshigh2023-11-28Python-Based Tool LSASS Process Access for Credential Dumping (Windows)
Alerts on process-access attempts to lsass.exe with a Python-related call trace and high granted access.
sigmaWindowshigh2023-11-27Windows HackTool Process Access: Detect Access by Common Tool Image Names
Alerts on Windows process access events initiated by processes whose image names match common credential/dumping hack tools.
sigmaWindowshigh2023-11-27wusa.exe Execution with Parent in Suspicious Windows Paths
Alerts when wusa.exe is spawned by a parent running from common suspicious Windows directories, excluding .msu-related noise.
sigmaWindowshigh2023-11-26Windows Registry IME File Value Used from Suspicious Paths
Alerts on Windows keyboard layout "Ime File" registry entries pointing to suspicious writable directory paths.
sigmaWindowshigh2023-11-21Windows Registry: Uncommon IME File Value in Keyboard Layouts Path
Alerts on Control\Keyboard Layouts\ registry values named "Ime File" that reference non-.ime extensions.
sigmaWindowshigh2023-11-21Windows Network Connections to Visual Studio Code Tunnels Domain
Alerts on initiated network connections to .tunnels.api.visualstudio.com from a Windows process.
sigmaWindowsmedium2023-11-20Windows Network Connections to *.devtunnels.ms
Alerts on initiated Windows network connections to .devtunnels.ms hostnames, which may indicate remote access use.
sigmaWindowsmedium2023-11-20Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
Alerts when excel.exe spawns foxprow.exe, schdplus.exe, or winproj.exe, consistent with suspicious Excel DCOM automation activity.
sigmaWindowshigh2023-11-13Windows: Command-Line Use of ms-appinstaller Protocol Handler for File Downloads
Alerts on Windows command lines invoking ms-appinstaller with an http source, indicating potential remote file download behavior.
sigmaWindowsmedium2023-11-09Windows msxsl.exe Execution with HTTP Keyword in Command Line
Flags execution of msxsl.exe when the command line includes an HTTP URL indicator.
sigmaWindowshigh2023-11-09Windows: File Download via msedge_proxy.exe Using HTTP/HTTPS URLs
Flags msedge_proxy.exe executions that include HTTP/HTTPS URLs, consistent with arbitrary file downloads.
sigmaWindowsmedium2023-11-09Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS
Alerts when IMEWDBLD.exe runs with an HTTP/HTTPS URL, indicating arbitrary file downloads.
sigmaWindowshigh2023-11-09