Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: ScreenConnect Temporary File Creation in ConnectWiseControl Temp
Flags file writes to ScreenConnect’s ConnectWiseControl\Temp staging directory from ScreenConnect.WindowsClient.exe.
sigmaWindowslow2023-10-10Windows Application: ScreenConnect RMM File Transfer Activity (Event 201)
Flags ScreenConnect RMM file transfer events on Windows based on provider name, Event ID 201, and transfer action text.
sigmaWindowslow2023-10-10Windows ScreenConnect Remote Command Execution (EventID 200)
Detects ScreenConnect command execution on Windows by matching EventID 200 with an 'Executed command of length' message.
sigmaWindowslow2023-10-10Windows Process Creation: CLI CommandLine References NTFS ::$index_allocation Stream
Flags Windows CLI commands referencing the NTFS ::$index_allocation stream for potential hidden directory activity.
sigmaWindowsmedium2023-10-09Windows Hidden Directory Creation Using NTFS $INDEX_ALLOCATION Stream
Alerts on Windows file events creating hidden NTFS content using the '::$index_allocation' alternate stream.
sigmaWindowsmedium2023-10-09Windows Kerberos KDC: Certificate used without strong user mapping
Alerts on Windows KDC certificate validation events lacking strong certificate-to-user mapping (Event 39/41).
sigmaWindowsmedium2023-10-09Windows Process Creation: Visual Studio Code Tunnel Execution with Renamed Binary
Flags Windows process executions that match renamed VS Code tunnel invocation patterns and related internal service startup.
sigmaWindowshigh2023-09-28Windows Service Registry Key ReadControl Access (Event ID 4663)
Flags READ_CONTROL access requests to service registry keys (\SYSTEM\ControlSet\Services\) via Windows Security Event 4663.
sigmaWindowslow2023-09-28Windows: AddInUtil.exe LoLBin Executed from Non-Standard Directory
Alerts when AddInUtil.exe (AddInUtil.exe) runs from an uncommon directory path on Windows.
sigmaWindowsmedium2023-09-18Windows Process Creation: Uncommon AddInUtil.exe Use of AddInRoot/PipelineRoot Paths
Alerts on AddInUtil.exe runs where AddInRoot/PipelineRoot command-line paths deviate from common VSTA locations.
sigmaWindowsmedium2023-09-18Windows: Uncommon Child Processes Spawned by Addinutil.exe
Alerts when Addinutil.exe launches an uncommon child process, indicating potential proxy execution abuse.
sigmaWindowsmedium2023-09-18Windows AddInUtil.exe Executed with Suspicious AddInRoot or PipelineRoot Parameters
Alerts on AddInUtil.exe runs using uncommon AddInRoot/PipelineRoot values targeting Temp, Desktop, Downloads, or public user paths.
sigmaWindowshigh2023-09-18Windows network connections initiated by AddinUtil.exe
Alerts on network connections initiated by Addinutil.exe, which is uncommon for this utility on Windows.
sigmaWindowshigh2023-09-18Windows: Diskshadow.exe Script Mode Execution from Suspicious File Paths
Alerts when diskshadow.exe runs with /s and a script path found in Temp/AppData/ProgramData/Users\Public-style directories.
sigmaWindowsmedium2023-09-15Windows Diskshadow Script Mode Executes Script File with Uncommon .txt Extension
Alerts when diskshadow.exe runs with -s script mode and the script path/command includes an uncommon extension like .txt.
sigmaWindowsmedium2023-09-15Suspicious Child Process Spawned by Diskshadow.exe (Windows Process Creation)
Alerts on process creation where Diskshadow.exe spawns certutil, cscript, mshta, PowerShell, regsvr32, rundll32, or wscript.
sigmaWindowsmedium2023-09-15Windows: Headless Chromium Browser Execution via --headless
Alerts on headless Chromium-based browser launches on Windows using the "--headless" command-line flag.
sigmaWindowslow2023-09-12Windows Process Creation: wmic.exe call terminate Attempt
Alerts on wmic.exe being executed with “call terminate”, indicating an attempt to terminate a process on Windows.
sigmaWindowsmedium2023-09-11Windows Process Creation: Execution of Renamed curl.exe via PE Metadata
Alerts on Windows process launches whose PE metadata matches curl.exe even when the executable image is renamed.
sigmaWindowsmedium2023-09-11Windows Chromium Headless Execution with Mockbin/Mocky URL
Alerts when a Chromium-based browser runs headless on Windows with a mockbin-like URL in the command line.
sigmaWindowshigh2023-09-11