Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: Uncommon Process Creates .rdp Remote Desktop File
Alerts on creation of .rdp files by processes that are not typically associated with producing them on Windows.
sigmaWindowshigh2023-04-18Windows winget Install from Zone.Identifier/WinGet Temp Contents Marked by Zone Transfer
Alerts on winget staging under Temp\WinGet combined with ZoneTransfer ZoneId=3 and Zone.Identifier ADS contents.
sigmaWindowshigh2023-04-18Windows Registry: Winget EnableLocalManifestFiles Set to DWORD 1
Flags setting the Winget AppInstaller local manifest installation policy (EnableLocalManifestFiles) to enabled.
sigmaWindowsmedium2023-04-17Windows winget AppInstaller admin_settings registry modification via winget.exe
Detects winget.exe-driven changes to AppInstaller admin_settings in the registry under LocalState\admin_settings.
sigmaWindowslow2023-04-17Windows Process: winget adds new download source via 'source add' with IP/endpoint
Alerts on winget.exe being used to add a new package download source specified by an IP address.
sigmaWindowsmedium2023-04-17Windows Winget adds HTTP package source
Alerts when winget is used to add a package source pointing to an http:// URL.
sigmaWindowshigh2023-04-17Windows: winget.exe adds new download sources via 'source add'
Alerts on winget.exe usage to add new package download sources using 'source add'.
sigmaWindowsmedium2023-04-17Windows Process Creation: Crassus Privilege Escalation Discovery Tool Execution
Identifies execution of the Crassus Windows privilege escalation discovery tool via process metadata.
sigmaWindowshigh2023-04-17Windows: Stracciatella.exe Process Execution Identification (SharpPick behavior)
Alerts on Windows process creation for Stracciatella.exe using PE metadata and known SHA256 hashes.
sigmaWindowshigh2023-04-17Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Flags Certipy.exe execution on Windows using PE metadata and Certipy-like AD CS command-line arguments.
sigmaWindowshigh2023-04-17Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Identifies Windows processes running Certify.exe with AD certificate abuse-oriented command line arguments.
sigmaWindowshigh2023-04-17Windows image_load Suspicious libvlc.dll DLL sideloading via non-VLC paths
Alerts when libvlc.dll is loaded from a non-default path, suggesting potential VLC DLL sideloading on Windows.
sigmaWindowsmedium2023-04-17Windows: Unexpected Termination of Message Queuing (MSMQ) Service via SCM Event 7034
Flags Service Control Manager Event ID 7034 for unexpected termination of the Message Queuing (MSMQ) service.
sigmaWindowshigh2023-04-14Windows Service Control Manager: Termination of Security-Critical Services With Error
Alerts on error-terminated Windows security and infrastructure services from Service Control Manager event 7023.
sigmaWindowshigh2023-04-14Windows Service Terminated With Error (Service Control Manager Event 7023)
Alerts on Windows services terminated with an error as reported by the Service Control Manager (EventID 7023).
sigmaWindowslow2023-04-14Windows: Renamed Visual Studio NodejsTools PressAnyKey.exe Execution
Flags Windows executions of renamed Microsoft.NodejsTools.PressAnyKey.exe to help spot LOLBIN-style abuse.
sigmaWindowsmedium2023-04-11Windows: Logged-On User Password Change via ksetup.exe
Flags ksetup.exe executions with /ChangePassword that may indicate a logged-on user password change on Windows.
sigmaWindowsmedium2023-04-06Windows Password Change via ksetup.exe /setcomputerpassword
Alerts on Windows ksetup.exe executions that set a computer password via /setcomputerpassword.
sigmaWindowsmedium2023-04-06Windows Defender Real-Time Protection Error or Restart (windefend Event 3002/3007)
Alerts on windefend events showing Defender Real-Time Protection feature errors (3002) or restarts (3007).
sigmaWindowsmedium2023-03-28Windows Process Creation: Sysinternals PsSuspend Targeting msmpeng.exe
Alerts on execution of Sysinternals PsSuspend with command line referencing msmpeng.exe.
sigmaWindowshigh2023-03-23