Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry: Disabling Antivirus Filter Driver on Dev Drive via FltmgrDevDriveAllowAntivirusFilter
Detects registry changes disabling antivirus minifilter inspection on a Dev Drive by setting the allow setting to 0x0.
sigmaWindowshigh2023-11-05Windows Registry: AllowAnonymousCallback Enabled for Anonymous Remote Connection
Alerts on setting AllowAnonymousCallback to 0x00000001 in the CIMOM key, enabling anonymous remote connections.
sigmaWindowsmedium2023-11-03Windows image load and execution of unsigned Thor scanner (thor.exe/thor64.exe)
Alerts on thor.exe/thor64.exe image loads on Windows where the Authenticode signature is missing or not from Nextron Systems.
sigmaWindowshigh2023-10-29Windows Process Creation: VS Code Tunnel (code-tunnel) Installed as a Service
Alerts on Windows process command lines consistent with installing VS Code tunnel (code-tunnel) as a service.
sigmaWindowsmedium2023-10-25Windows: VS Code Tunnel Launching PowerShell or WSL/Bash Shell
Flags VS Code tunnel (node.exe) spawning PowerShell, WSL, or bash shell processes on Windows.
sigmaWindowsmedium2023-10-25Windows Process Creation: Visual Studio Code Tunnel (.exe tunnel) Execution
Flags cmd.exe-launched Visual Studio Code tunnel processes with expected tunnel and license-accept arguments on Windows.
sigmaWindowsmedium2023-10-25Windows file creation of code_tunnel.json outside Code/VsCode executables
Alerts on creation of code_tunnel.json on Windows when it isn’t created by typical VS Code binaries.
sigmaWindowshigh2023-10-25Windows File Creation by VS Code Tunnel node.exe in .vscode-server History
Alerts on node.exe creating files under .vscode-server User History when the process runs from a VS Code server tunnel path.
sigmaWindowsmedium2023-10-25Windows DNS Queries to Visual Studio Code Tunnel Domains
Alerts on Windows DNS queries to .tunnels.api.visualstudio.com, matching Visual Studio Code tunnel endpoints.
sigmaWindowsmedium2023-10-25Windows DNS Queries to Devtunnels .devtunnels.ms Domains
Alerts on Windows DNS queries for .devtunnels.ms domains, which may indicate DevTunnels-based C2 or persistence.
sigmaWindowsmedium2023-10-25Windows Process Execution of findstr.EXE for Security Tool Keyword Filtering
Alerts on Windows findstr.exe executions that filter output using security software and antivirus-related keywords.
sigmaWindowsmedium2023-10-20Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
sigmaWindowshigh2023-10-19Windows PowerShell EnableScripts Policy Enabled via Registry DWORD
Flags registry changes that enable PowerShell script execution via the EnableScripts policy (DWORD 0x00000001).
sigmaWindowslow2023-10-18Windows Process Execution: curl.exe Downloading Files From an IP URL
Flags curl.exe commands that download via an IP-based URL using output/remote-name flags.
sigmaWindowsmedium2023-10-18Windows CertOC.exe Downloads File From IP-Based URL Using -GetCACAPS
Flags CertOC.exe executions using an IP-based URL in the command line with -GetCACAPS.
sigmaWindowshigh2023-10-18Windows Process Creation: CoercedPotato.exe Execution via ExploitId Parameters
Flags Windows process creation for CoercedPotato.exe with --exploitId and known IMPHASH values.
sigmaWindowshigh2023-10-11Windows Named Pipe Creation with "\coerced\" PipeName Segment
Detects Windows named pipe creations where the pipe name contains the '\coerced\' pattern.
sigmaWindowshigh2023-10-11Windows MSSQL Failed Logon (EventID 18456) From External Client IP
Alerts on MSSQL failed login attempts (Event 18456) from client IPs outside typical local/private ranges.
sigmaWindowsmedium2023-10-11Windows MSSQL Failed Logon (Event ID 18456) Detection
Alerts on MSSQL-related failed login attempts (Event ID 18456) captured in Windows application logs.
sigmaWindowslow2023-10-11Windows ScreenConnect RMM System Command Execution via cmd.exe
Flags cmd.exe launched by ScreenConnect.ClientService.exe with a TEMP\ScreenConnect command-line path.
sigmaWindowslow2023-10-10