Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
sigmaWindowshigh2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
sigmaWindowshigh2026-01-26Windows Registry: Alert on Changes to \shell\open\command Targeting Common Malware Paths
Alerts on registry_set events modifying \shell\open\command to point to suspicious temp/user-writable locations.
sigmaWindowsmedium2026-01-24Windows Registry Modification: OracleOciLib/OracleOciLibPath Under MSDTC for oci.dll Redirection
Alerts on MSDTC MTxOCI registry changes to OracleOciLib/OracleOciLibPath that may redirect oci.dll loading to attacker-controlled locations.
sigmaWindowshigh2026-01-24Windows cmd.exe Executing start Utility with Hidden Window Flags (/b or /min)
Alerts on cmd.exe invoking start.exe with /b or /min, especially when directed at scripts or files in suspicious temp/public paths.
sigmaWindowsmedium2026-01-24Windows Registry Query for System Language Using reg.exe
Flags reg.exe registry queries to Control\Nls\Language, indicating system language discovery on Windows.
sigmaWindowsmedium2026-01-09Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Alerts when reg.exe or PowerShell modifies User Shell Folders/Shell Folders Startup-related registry values.
sigmaWindowshigh2026-01-05Windows: Kernel Driver Utility (KDU) and hamakaze.exe Execution
Alerts on KDU/hamakaze.exe launches with command-line parameters associated with kernel driver loading.
sigmaWindowshigh2026-01-02Windows devcon.exe Command Line Disabling VMware VMCI Device
Flags devcon.exe command lines that disable VMware VMCI using VMCI PCI ID or VMWVMCIHOSTDEV driver markers.
sigmaWindowshigh2026-01-02Windows Registry Set: Disable Windows Credential Guard by Zeroing EnableVirtualizationBasedSecurity
Alerts on registry value changes that zero Credential Guard/LSA configuration flags to disable virtualization-based secret protection.
sigmaWindowshigh2025-12-26Windows Registry Delete of Credential Guard EnableVirtualizationBasedSecurity or LsaCfgFlags
Flags deletion of Credential Guard/LSA-related registry values that may weaken virtualization-based secret protection.
sigmaWindowshigh2025-12-26Windows Credential Guard Registry Key Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/Reg.exe commands that add/modify/delete DeviceGuard/LSA registry values tied to Credential Guard.
sigmaWindowshigh2025-12-26Windows AMSI Disabled by Registry Value Modification (AmsiEnable)
Alerts when Windows Script Settings AmsiEnable is set to 0x00000000 to disable AMSI.
sigmaWindowshigh2025-12-25Windows Process Creation: Registry Modification to Disable ETW AutoLogger via reg.exe or PowerShell
Flags reg.exe or PowerShell registry changes aimed at disabling WMI AutoLogger EventLog session components.
sigmaWindowshigh2025-12-25Windows Process Command-Line Tampering of AMSI Registry Values via reg.exe or PowerShell
Alerts on reg.exe or PowerShell command lines attempting to add/set AMSI enable registry settings.
sigmaWindowshigh2025-12-25Windows File Events: Legitimate Applications Writing Executables to Uncommon Locations
Alerts when selected Windows binaries write files to typically uncommon directories such as Temp, ProgramData, AppData, or system areas.
sigmaWindowshigh2025-12-10Windows GitHub Self-Hosted Runner Execution via Runner.Worker and Runner.Listener
Alerts on Windows process activity from GitHub self-hosted runner Worker/Listener indicating spawnclient or run/configure operations.
sigmaWindowsmedium2025-11-29Windows Schtasks Execution with Renamed schtasks.exe Binary
Alerts on scheduled task management commands that use a renamed schtasks.exe binary on Windows.
sigmaWindowshigh2025-11-27Windows Process Access: WerFaultSecure accessing MsMpEng with dbgcore.dll/dbghelp.dll call traces
Alerts on WerFaultSecure.exe accessing MsMpEng.exe with dbgcore/dbghelp DLLs in the call trace.
sigmaWindowshigh2025-11-27Windows suspicious access to LSASS.exe with dbgcore.dll/dbghelp.dll call trace from uncommon paths
Alerts on suspicious LSASS access from unusual locations when dbgcore.dll or dbghelp.dll appears in the call trace.
sigmaWindowshigh2025-11-27