Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows DLL Sideloading via CCleanerDU.dll ImageLoad from CCleaner Folder
Alerts when CCleanerDU.dll is loaded, but the loading image is not CCleaner executables in standard install paths.
sigmaWindowsmedium2023-07-13Windows Process Creation From Fake Recycle.Bin Directories
Alerts on Windows processes launched from fake RECYCLER.BIN / RECYCLERS.BIN folder paths often used for stealth.
sigmaWindowshigh2023-07-12Windows: wordpad.exe Initiated Network Connections on Uncommon Ports
Alerts when wordpad.exe initiates outbound connections on destination ports outside common C2-related ports.
sigmaWindowsmedium2023-07-12Windows Office Apps Initiating Network Connections to Non-Common Ports
Alerts on network connections initiated by Windows Office apps to destination ports not in the common port set.
sigmaWindowsmedium2023-07-12Windows: Suspicious File Creation in Fake RECYCLER.BIN Staging Folders
Alerts on Windows file writes involving RECYCLERS.BIN\ or RECYCLER.BIN\ paths often used for staging.
sigmaWindowshigh2023-07-12Windows DLL Sideloading via Abusable DLLs Loaded from Suspicious Locations
Flags Windows module loads of specific abusable DLL names from public, temp, or user folders consistent with potential DLL sideloading.
sigmaWindowshigh2023-07-11Windows: Recon command output piped to findstr.exe
Alerts on Windows command lines running recon commands whose output is filtered with findstr.exe.
sigmaWindowsmedium2023-07-06Windows process creation: WerFault.exe executed with -pr flag
Alerts when WerFault.exe is launched with the -pr argument, potentially indicating ReflectDebugger-based execution.
sigmaWindowsmedium2023-06-30Windows PowerShell Decryption-Like Activity Involving .LNK File Processing
Identifies PowerShell runs that enumerate and process *.lnk content using byte-level reads/writes consistent with decryption staging.
sigmaWindowshigh2023-06-30Windows Process Execution of curl.exe with --insecure Flag
Flags curl.exe launched with --insecure/-k to disable TLS certificate verification.
sigmaWindowsmedium2023-06-30Windows Registry: Uncommon Microsoft Office Trusted Location Path Added
Alerts on registry changes adding non-standard Microsoft Office Trusted Location paths that could undermine macro security.
sigmaWindowshigh2023-06-21Windows Registry TrustRecords Change for Macro-Enabled Documents in Suspicious Paths
Alert on Windows registry changes to Office TrustRecords where trusted-document paths fall in suspicious directories.
sigmaWindowshigh2023-06-21Windows: Office Executable Running a Document from Trusted Template/Startup Paths
Alerts when Office apps are launched with command lines pointing to documents under Office template/Startup paths.
sigmaWindowshigh2023-06-21Windows rundll32.exe Using ShellExecute via ShellDispatch.dll Functionality
Alerts on rundll32.exe command lines referencing RunDll_ShellExecuteW, suggesting ShellDispatch.dll ShellExecute-based execution.
sigmaWindowsmedium2023-06-20Windows ShellDispatch.dll DLL Sideloading via Image Load Monitoring
Alerts on suspicious loads of ShellDispatch.dll on Windows when not occurring in expected temp directories.
sigmaWindowsmedium2023-06-20Windows DLL side-loading via appverifUI.dll image loads
Alerts when appverifUI.dll is loaded on Windows from unexpected paths, a common DLL sideloading technique.
sigmaWindowshigh2023-06-20Windows Security 4719: Important Audit Policy Categories Disabled
Alerts on Windows Security 4719 indicating auditing was disabled for important security event subcategories.
sigmaWindowshigh2023-06-20Windows Virtual Smart Card Created Using TpmVscMgr.EXE
Flags execution of Tpmvscmgr.exe with a create command, indicating creation of a new virtual smart card.
sigmaWindowsmedium2023-06-15Windows: Detect lodctr.exe Rebuild (-r) Performance Counter Values
Flags lodctr.exe executions with -r, indicating attempts to rebuild performance counter registry values.
sigmaWindowsmedium2023-06-15Windows VMwareToolBoxCmd.exe Script/Set Execution Used for VM State Persistence
Alerts on VMwareToolBoxCmd.exe launched with script/set flags and command-line hints of a suspicious VM state persistence setup.
sigmaWindowshigh2023-06-14