Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: File creation of a Procmon-named .sys driver by non-procmon processes
Alerts when a procmon-named .sys driver is created by a process other than procmon.
sigmaWindowsmedium2023-05-05Windows: Process Explorer Driver (.sys) Creation by Non-Process Explorer Process
Alerts on creation of PROCEXP-named .sys drivers by processes other than Process Explorer.
sigmaWindowshigh2023-05-05Windows Suspicious File Creation in C:\PerfLogs with Executable/Script Extensions
Alerts on creation of potentially malicious file types in C:\PerfLogs\ on Windows.
sigmaWindowsmedium2023-05-05Windows: File Creation of NTDS.DIT (Active Directory Database)
Flags creation of an ntds.dit file on Windows, an Active Directory database artifact often associated with credential access.
sigmaWindowslow2023-05-05Windows Process: sqlcmd.exe Querying Veeam Backup Databases
Flags sqlcmd.exe command lines querying Veeam backup database objects associated with repository and credential data.
sigmaWindowsmedium2023-05-04Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
sigmaWindowscritical2023-05-04Windows PowerShell Credential Dumping Script Targeting Veeam Backup ProtectedStorage
Alerts on PowerShell scripts that reference Veeam protected storage and credential extraction indicators, enabling stored credential dumping on Windows.
sigmaWindowshigh2023-05-04Windows Non-Browser Process Network Connection to api.notion.com
Alerts when a non-browser Windows process connects to api.notion.com, excluding common browsers and the Notion desktop app.
sigmaWindowslow2023-05-03Windows Suspicious Non-Browser Network Connections to Google API Endpoints
Alerts on suspicious Windows processes connecting to Google API hostnames, excluding common browsers and known benign apps.
sigmaWindowsmedium2023-05-01Windows Winlogon Outbound Network Connections to Public IPs
Flags outbound connections initiated by winlogon.exe to non-local public destination IPs on Windows.
sigmaWindowsmedium2023-04-28Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Identifies PowerShell ScriptBlock content that includes Rubeus-specific Kerberos and ticket manipulation flags.
sigmaWindowshigh2023-04-27Windows Security: Security-Enabled Global Group Deletion (Event ID 4730/634)
Alerts on Windows Security audit events indicating a security-enabled global group was deleted.
sigmaWindowslow2023-04-26Windows Security Log: Member Removed from Security-Enabled Global Group
Flags Windows Security Log events showing a member was removed from a security-enabled global group.
sigmaWindowslow2023-04-26Windows Security: Member Added to Security-Enabled Global Group
Alerts when Windows logs show a user was added to a security-enabled global group via Event ID 4728 or 632.
sigmaWindowslow2023-04-26Suspicious Windows Network Connections to External IP Lookup Service APIs
Alerts on non-browser outbound connections from Windows hosts to public IP lookup API domains.
sigmaWindowsmedium2023-04-24Windows PowerShell Invoke-WebRequest Execution via Direct IP in Command Line
Alerts when PowerShell executes web-request aliases targeting direct IP URLs, indicating possible remote content access.
sigmaWindowsmedium2023-04-21Windows Scheduled Task Creation with Schtasks -XML Using Non-.xml File
Alerts when schtasks.exe creates a scheduled task using -XML but the referenced file does not end with .xml.
sigmaWindowsmedium2023-04-20Windows RDP client Mstsc.EXE launched from uncommon browser or email parent process
Alerts when mstsc.exe is spawned by a browser or Outlook, suggesting potential RDP access using a local .rdp file.
sigmaWindowshigh2023-04-18Windows mstsc.exe launched with a local .rdp file from suspicious paths
Alerts on mstsc.exe executions that use a local .rdp file referenced from suspicious command-line paths.
sigmaWindowshigh2023-04-18Windows mstsc.exe launched with local .rdp file argument
Alerts on mstsc.exe executions that reference local .rdp files via the command line.
sigmaWindowslow2023-04-18