Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: VMwareToolBoxCmd.exe script/set Used to Configure VM State Persistence
Flags VMwareToolBoxCmd.exe use of 'script' and 'set' parameters consistent with VM state–based persistence.
sigmaWindowsmedium2023-06-14Windows DLL Sideloading: waveedit.dll Loaded by Nero WaveEditor
Alerts when waveedit.dll is loaded from an unexpected path, suggesting possible DLL sideloading on Windows.
sigmaWindowshigh2023-06-14Windows Registry: ClickOnce Trust PromptingLevel Set to Enabled for Multiple Locations
Alerts on Enabled ClickOnce trust prompting registry changes for Internet and related locations.
sigmaWindowsmedium2023-06-12Suspicious Child Process Spawned by ClickOnce Application (Windows)
Alerts when a ClickOnce app under AppData\Local\Apps\2.0\ spawns common script/tool executables.
sigmaWindowsmedium2023-06-12Windows: Uncommon Child Processes Spawned by SndVol.exe
Alerts when SndVol.exe launches unusual child processes, using Windows process creation logs.
sigmaWindowsmedium2023-06-09Windows: Potential RjvPlatform.dll DLL Sideloading via SystemResetPlatform.exe from Non-Default Path
Flags SystemResetPlatform.exe loading RjvPlatform.dll from a non-default location, indicating possible DLL sideloading.
sigmaWindowshigh2023-06-09Windows: RjvPlatform.dll loaded by SystemResetPlatform.exe from $SysReset path
Alerts on SystemResetPlatform.exe loading RjvPlatform.dll from the $SysReset Framework Stack path on Windows.
sigmaWindowsmedium2023-06-09Windows DLL Sideloading Suspicion via edputil.dll Image Load
Alerts on edputil.dll image loads occurring outside standard Windows system directories, suggesting possible DLL side-loading.
sigmaWindowshigh2023-06-09Windows DLL Sideloading Indicators: 7za.dll Loaded from Non-Program Files Paths
Alerts when a process loads 7za.dll from a non-Program Files path, indicating potential DLL sideloading.
sigmaWindowslow2023-06-09Windows ClickOnce Loads Unsigned or Expired Signed Modules from User Apps Path
Alerts when a ClickOnce app loads a module from Apps\2.0 that is unsigned or has an expired signature.
sigmaWindowsmedium2023-06-08Windows Registry COM InProcServer32 Hijack via PSFactory CLSID Default Value
Detects suspicious modifications to a PSFactory COM InProcServer32 (Default) registry value that may enable COM-based persistence.
sigmaWindowshigh2023-06-07Windows Code Integrity: Kernel Module Loaded Without WHQL Requirements (Event 3082/3083)
Alerts when Code Integrity logs show loaded kernel modules failing WHQL compliance (Event 3082/3083), excluding selected VMware drivers.
sigmaWindowshigh2023-06-06Windows Code Integrity Operational: Unsigned Image Loaded
Alerts on Windows Code Integrity detecting that an unsigned image was loaded (Event ID 3037).
sigmaWindowshigh2023-06-06Windows Code Integrity Unsigned Kernel Module Loaded (Event ID 3001)
Alerts on Windows Code Integrity reporting an unsigned kernel module load via Event ID 3001.
sigmaWindowshigh2023-06-06Windows Code Integrity: Revoked Signed Image Loaded (Event 3032/3035)
Alerts on Code Integrity events showing a revoked signed image was loaded, including debugger-allowed cases.
sigmaWindowshigh2023-06-06Windows Code Integrity blocks image load when signing certificate is revoked (Event ID 3036)
Alerts on Windows Code Integrity Event ID 3036 when image loads are blocked because the signing certificate is revoked.
sigmaWindowshigh2023-06-06Windows Code Integrity: Revoked Kernel Driver Loaded (Event 3021/3022)
Alerts when Windows Code Integrity reports a revoked kernel driver/module loaded (including debugger-allowed cases) via Event IDs 3021/3022.
sigmaWindowshigh2023-06-06Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Flags Code Integrity Operational events where Windows blocks loading a revoked (untrusted) driver certificate.
sigmaWindowshigh2023-06-06Windows Code Integrity blocked disallowed file for protected processes (Event ID 3104)
Alerts on Windows Code Integrity Event ID 3104 when a disallowed file is blocked for protected processes.
sigmaWindowshigh2023-06-06Windows Process Creation: Renamed AutoIt2/AutoIt3 Execution via AutoIt3ExecuteScript
Alerts on suspicious renamed AutoIt2/AutoIt3 execution based on command-line parameters plus known hashes and original file names.
sigmaWindowshigh2023-06-04