Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: certutil.exe Encodes Files to Base64 Using -encode With Suspicious Extensions
Alert on certutil.exe -encode activity that targets files with suspicious extensions.
sigmaWindowshigh2023-05-15Windows DLL Sideloading: goopdate.dll Loaded from Nonstandard Paths
Alerts when goopdate.dll is loaded from non-standard locations, suggesting possible DLL sideloading behavior on Windows.
sigmaWindowsmedium2023-05-15Windows RoboForm DLL Sideloading via ImageLoaded roboform.dll/roboform-x64.dll
Alerts on loaded roboform*.dll modules on Windows when module loading is not matched to expected RoboForm binaries.
sigmaWindowsmedium2023-05-14Windows Certificate Export from Local Certificate Store (Event ID 1007)
Flags Windows events where a certificate is exported from the local certificate store via Certificate Services client telemetry.
sigmaWindowsmedium2023-05-13Windows CAPI2 Event 70: Certificate Private Key Acquired
Detects when Windows CAPI2 logs that a process acquired a certificate private key (EventID 70).
sigmaWindowsmedium2023-05-13Windows Excel Loads .XLL Add-in from Uncommon File Paths
Flags Excel loading .xll add-ins from uncommon directories based on image load paths.
sigmaWindowsmedium2023-05-12Windows: WinSxS .exe Creation Triggered by Non-System Process
Flags .exe creation in C:\Windows\WinSxS\ when the creating process is not from standard system directories.
sigmaWindowsmedium2023-05-11PowerShell ScriptBlock Function Get-VMRemoteFXPhysicalVideoAdapter Module Creation
Flags PowerShell module content that defines Get-VMRemoteFXPhysicalVideoAdapter in a ScriptBlock, consistent with load-order abuse patterns.
sigmaWindowshigh2023-05-09Windows: New PowerShell Module Files Created by Non-PowerShell Processes
Detects new PowerShell module files written into Modules directories by processes other than expected PowerShell hosts.
sigmaWindowsmedium2023-05-09Windows PowerShell Module File Creation via PowerShell Processes
Alert when PowerShell creates module-related files under WindowsPowerShell or PowerShell 7 module directories.
sigmaWindowslow2023-05-09Windows PowerShell dropping a .ps1 script from powershell.exe or pwsh.exe
Alerts when PowerShell creates a dropped .ps1 script file on Windows, excluding common benign temp and test outputs.
sigmaWindowslow2023-05-09System Informer Execution on Windows Process Creation
Alerts on Windows executions of SystemInformer.exe using matching filenames, metadata, and known hashes.
sigmaWindowsmedium2023-05-08Windows File Event: Flag Cyrillic Homoglyph Characters in Target Filename
Alerts on Windows file events with TargetFilename containing ASCII lookalike Unicode characters.
sigmaWindowsmedium2023-05-08Windows PUA System Informer Driver Load via SystemInformer.sys
Alerts on loading SystemInformer.sys as a Windows driver when matched against known System Informer SHA256 hashes.
sigmaWindowsmedium2023-05-08Windows Process Command Line Matches Perfect Homoglyph Unicode Characters
Alerts when a Windows process command line includes Unicode homoglyphs that look like ASCII letters.
sigmaWindowsmedium2023-05-07Windows ImageLoad of SolidPDFCreator.dll from Unexpected Paths
Alerts when SolidPDFCreator.dll is loaded from a non-standard process or path, consistent with potential DLL sideloading.
sigmaWindowsmedium2023-05-07Windows Wget.exe Downloads From File-Sharing Domains Matching Suspicious Output Flags
Flags wget.exe executions on Windows that download via HTTP from known file-sharing domains and write specific file extensions to disk.
sigmaWindowshigh2023-05-05Windows curl.exe Downloads from File-Sharing Domains with Suspicious Output Extensions
Alerts on curl.exe downloading files over HTTP from file-sharing/content hosting domains, based on process command-line and executable context.
sigmaWindowshigh2023-05-05PowerShell Script Reading Files and Resolving DNS Host Entries
Identifies PowerShell scripts that read files, resolve DNS host entries, and output results to disk.
sigmaWindowsmedium2023-05-05Windows DLL Sideloading: libcurl.dll Loaded by gup.exe from Uncommon Location
Alerts when gup.exe loads libcurl.dll from a path that doesn’t match the excluded Notepad++ GUP.exe location.
sigmaWindowsmedium2023-05-05