Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Suspicious Creation of .dmp/.hdmp Files by Shell or Script Hosts
Alerts on .dmp/.dump/.hdmp file creation by common Windows shells and scripting engines.
sigmaWindowsmedium2023-09-07Windows Registry: Enabled TLS 1.0 or TLS 1.1 via SCHANNEL Protocols Enabled=1
Flags registry changes that set SCHANNEL TLS 1.0/1.1 Enabled to 1 on Windows.
sigmaWindowsmedium2023-09-05Windows Registry ZoneMap ProtocolDefaults Downgraded to My Computer for HTTP/HTTPS
Flags IE/Windows ZoneMap changes setting HTTP/HTTPS ProtocolDefaults DWORD 0x00000000 to the My Computer zone.
sigmaWindowshigh2023-09-05Suspicious CommandLine Parameters for Electron Apps on Windows
Alerts on Electron app execution with command-line flags consistent with subprocess and renderer/utility launching behavior.
sigmaWindowsmedium2023-09-05Windows Process Creation: IE ZoneMap ProtocolDefaults downgraded to My Computer for HTTP/HTTPS
Flags Windows command lines that set IE ZoneMap ProtocolDefaults for HTTP to the My Computer (zone 0) trust level.
sigmaWindowshigh2023-09-05Windows: Detect VMMap loading a signed dbghelp.dll from C:\Debuggers\
Alerts on vmmap.exe/vmmap64.exe loading a signed dbghelp.dll from C:\Debuggers, consistent with potential DLL sideloading.
sigmaWindowsmedium2023-09-05Windows: Zone.Identifier Alternate Data Stream Deleted by Uncommon Application
Alert on deletion of the Zone.Identifier ADS by an uncommon process on Windows.
sigmaWindowsmedium2023-09-04Suspicious Child Process Spawned by WinRAR.exe on Windows
Alerts when WinRAR.exe launches command, scripting, or proxy execution binaries on Windows.
sigmaWindowsmedium2023-08-31Suspicious LOLBIN Copy From Windows System Directories Using Windows Copy Tools
Flags cmd/PowerShell/robocopy/xcopy commands that copy known LOLBINs out of System32/SysWOW64/WinSxS.
sigmaWindowshigh2023-08-29Windows Process Watch: PythonFunctionWarnings Disabled via Excel Security Registry Setting
Flags Excel-related process command lines that disable Python function execution warnings via PythonFunctionWarnings=0.
sigmaWindowshigh2023-08-22Windows Process Execution Triggered from WebDAV LNK Paths
Alerts on explorer.exe launching cmd/cscript/mshta/powershell/wscript/pwsh when the command line references a WebDAV \DavWWWRoot\ LNK path.
sigmaWindowsmedium2023-08-21Windows Registry: New BgInfo UserFields value enabling custom WMI query execution
Alerts on new BgInfo UserFields registry entries that appear to configure a custom WMI query.
sigmaWindowsmedium2023-08-16Windows Registry: New BgInfo UserFields value enabling custom VBScript execution
Detects registry changes under BgInfo UserFields that can be configured to run custom VBScript via BgInfo.exe.
sigmaWindowsmedium2023-08-16Windows Registry Set: New BgInfo Database Path Value
Detects registry writes under BgInfo database configuration that set a new external database path.
sigmaWindowsmedium2023-08-16Suspicious Child Process Creation from BgInfo.EXE on Windows
Alerts when BgInfo.exe spawns suspicious calc/cmd/cscript/mshta/powershell/wscript or runs from common AppData/Temp paths.
sigmaWindowshigh2023-08-16Windows Bash.exe Launched Without Script Execution Arguments
Alerts on bash.exe launched without script-execution flags, a potential stealthy way to run bash-driven payloads on Windows.
sigmaWindowsmedium2023-08-15Suspicious aspnet_compiler.exe Execution from User or Temp Paths on Windows
Alerts when aspnet_compiler.exe runs with command lines indicating user-writable or temp/task paths.
sigmaWindowshigh2023-08-14Suspicious Child Process of aspnet_compiler.exe on Windows
Alerts when aspnet_compiler.exe spawns calc/notepad or executes from public/temp/Task-related paths on Windows.
sigmaWindowshigh2023-08-14Windows: Detect aspnet_compiler.exe Creating Temporary Assembly DLLs
Alerts when aspnet_compiler.exe writes a new DLL into the Temporary ASP.NET assembly tmp directories.
sigmaWindowsmedium2023-08-14Windows DLL sideloading via unsigned mfdetours.dll loaded by image_load
Alerts on loading unsigned \mfdetours.dll, consistent with DLL sideloading abuse via mftrace.exe.
sigmaWindowshigh2023-08-11