Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Security Event 4661 Password Policy Enumeration via ReadPasswordParameters
Flags Windows Event 4661 activity indicating password policy enumeration (ReadPasswordParameters on Security Account Manager).
sigmaWindowsmedium2023-05-19Windows WerFault ReflectDebugger Registry Key Value Targeting
Flags registry set events targeting WerFault ReflectDebugger under Windows Error Reporting Hangs for potential persistence abuse.
sigmaWindowshigh2023-05-18PowerShell Certificate Export Cmdlets in Windows Process Creation
Flags PowerShell command lines invoking certificate export cmdlets (Export-PfxCertificate/Export-Certificate) on Windows.
sigmaWindowsmedium2023-05-18Windows WWlib.DLL sideloading via Office process loading behavior
Alert on Windows image-load events where winword-associated processes load wwlib.dll outside expected Office paths.
sigmaWindowsmedium2023-05-18Windows CreateStreamHash: Suspicious Embedded File Download Indicators via .zip TLD
Flags Windows downloads indicating .zip/ plus ':Zone' in target filenames for risky executable or script extensions.
sigmaWindowshigh2023-05-18Windows: Rundll32 Executions Using Obfuscated Ordinal Call Arguments
Flags rundll32.exe launches with command-line ordinal obfuscation patterns.
sigmaWindowsmedium2023-05-17Windows: Suspicious rundll32 Execution of advpack.dll with Ordinal RegisterOCX Calls
Identifies rundll32.exe launching advpack.dll with ordinal-style calls consistent with stealthy OCX registration behavior.
sigmaWindowshigh2023-05-17Windows Process Creation: cloudflared Tunnel Execution with Config and Credentials Flags
Alerts on Windows processes running cloudflared tunnels with config and token/credential flags.
sigmaWindowsmedium2023-05-17Windows: Detect cloudflared tunnel cleanup command execution
Flags Windows executions of cloudflared with tunnel cleanup and connector/config parameters.
sigmaWindowsmedium2023-05-17Windows Registry: Internet Explorer DisableFirstRunCustomize Set via Explorer or ie4uinit
Alerts on Windows registry writes to Internet Explorer DisableFirstRunCustomize that change first-run wizard customization states.
sigmaWindowsmedium2023-05-16Windows LiveKD Kernel Memory Dump Attempt via "-m" Flag
Flags LiveKD executions with the "-m" option that may trigger kernel memory dumping on Windows.
sigmaWindowshigh2023-05-16Windows LiveKD Driver File Creation by Uncommon Process Image
Alerts when LiveKdD.SYS is created by a process other than livekd.exe/livek64.exe on Windows.
sigmaWindowshigh2023-05-16Windows LiveKD Driver Creation via LiveKdD.SYS and LiveKD Executable Launch
Detects creation of LiveKdD.SYS in the Windows drivers directory by LiveKD executables.
sigmaWindowsmedium2023-05-16Windows: LiveKD kernel memory dump file creation (livekd.dmp)
Flags creation of C:\Windows\livekd.dmp, a default LiveKD kernel memory dump file name.
sigmaWindowshigh2023-05-16Windows Wscript/Cscript Executes Files with Uncommon Non-Script Extensions
Flags wscript.exe/cscript.exe launching files named with uncommon non-script extensions via command-line content.
sigmaWindowshigh2023-05-15Suspicious rundll32/regsvr32/msiexec Child Process from Windows Script Hosts (cscript/wscript)
Alerts on wscript/cscript spawning suspicious child processes or scripts that invoke rundll32/regsvr32/msiexec.
sigmaWindowsmedium2023-05-15Windows Process Creation: LiveKD Execution Suggesting Potential Memory Dumping
Detects launching LiveKD (livekd.exe/livekd64.exe) on Windows via image path or PE OriginalFileName metadata.
sigmaWindowsmedium2023-05-15Windows Process Creation of Kernel Debugger kd.exe
Flags Windows process creations that run kd.exe using image path and OriginalFileName metadata.
sigmaWindowsmedium2023-05-15Suspicious Child Process of GoogleUpdate.exe on Windows
Alerts when GoogleUpdate.exe spawns an unexpected child process on Windows, using parent/child image telemetry and allowlisting common Google updaters.
sigmaWindowshigh2023-05-15Windows Process Creation: certutil.exe Encodes Files to Base64 in Suspicious Paths
Alert on certutil.exe running with -encode when the command line references files under suspicious directories.
sigmaWindowshigh2023-05-15