Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Sysinternals PsSuspend Process Execution
Alerts on execution of Sysinternals PsSuspend on Windows via process creation events.
sigmaWindowsmedium2023-03-23Windows DLL sideloading: iviewers.dll loaded from non-Windows Kits paths
Alerts on unexpected loads of iviewers.dll outside Windows Kits paths, consistent with DLL sideloading attempts.
sigmaWindowshigh2023-03-21Windows PowerShell File Dropper Activity: Creating Executables or Script Files
Alerts when PowerShell writes .exe/.dll or script-like files, consistent with binary/script staging or dropping.
sigmaWindowsmedium2023-03-17Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
Alerts on svchost.exe launching rundll32.exe to run davclnt.dll DavSetCookie for WebDav over a non-local IP.
sigmaWindowshigh2023-03-16Windows Registry: Hypervisor Enforced Code Integrity Enabled DWORD Set to 0
Alerts when HVCI-related registry values are set to 0, indicating Hypervisor Enforced Code Integrity has been disabled.
sigmaWindowshigh2023-03-14Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
sigmaWindowshigh2023-03-14Windows: Sysinternals ADExplorer invoked with snapshot flag to create AD database snapshot
Flags Sysinternals ADExplorer running with "snapshot" to create a local Active Directory database copy.
sigmaWindowsmedium2023-03-14Windows AD Structure Export Using ldifde.exe with -f
Flags ldifde.exe executions using -f that indicate Active Directory structure export from a Windows host.
sigmaWindowsmedium2023-03-14Windows Process Creation: dotnet-dump.exe collect Flag
Flags dotnet-dump.exe executions using the collect parameter, which may indicate memory dumping of sensitive processes.
sigmaWindowsmedium2023-03-14Windows: Detect csvde.exe Active Directory export to CSV
Flags csvde.exe executions on Windows that include -f, consistent with exporting Active Directory data for discovery.
sigmaWindowsmedium2023-03-14Windows Registry Event for Potential Qakbot/IceID Persistence Key
Alerts on Windows registry events referencing a specific \\Software\\firm\\soft\\Name key suffix linked to Qakbot/IceID-like activity.
sigmaWindowshigh2023-03-13Windows Rundll32 Execution Masquerading as Image Files via Image Extensions
Flags rundll32.exe executions whose command line references image file extensions used for DLL masquerading.
sigmaWindowshigh2023-03-13Windows PowerShell Downloading DLLs via Invoke-WebRequest or Invoke-RestMethod
Alerts on PowerShell using web request cmdlets to download an HTTP DLL to disk.
sigmaWindowsmedium2023-03-13PowerShell GzipStream Decompression Attempts on Windows
Detects Windows PowerShell commands using GZipStream and ::Decompress to decompress encoded Gzip data.
sigmaWindowsmedium2023-03-13Windows Wazuh Platform DLL Side-Loading via ImageLoad of libwazuhshared.dll
Alerts on suspicious loading of Wazuh platform DLLs in Windows image load telemetry, excluding common Program Files and Mingw64 patterns.
sigmaWindowsmedium2023-03-13Windows Rcdll.dll DLL Sideloading via Image Load Path
Flags rcdll.dll loads from unexpected locations, excluding Visual Studio and Windows Kits directories.
sigmaWindowshigh2023-03-13Windows Sysmon Configuration Update via Sysmon64 Command-Line
Flags execution of Sysmon binaries with '-c', indicating a Sysmon configuration update attempt.
sigmaWindowsmedium2023-03-09Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
sigmaWindowshigh2023-03-08Windows cmd.exe Reads Input from STDIN Using '<' Redirection
Flags cmd.exe invocations with '<' in the command line, indicating stdin/input redirection.
sigmaWindowsmedium2023-03-07Windows: Stop a Service with sc.exe via Process Creation (sc.exe stop)
Identifies sc.exe executions that include 'stop' to stop Windows services based on process creation and command line.
sigmaWindowslow2023-03-05