Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell Stop-Service Used to Stop a Service
Flags PowerShell executions that include the Stop-Service cmdlet to stop a Windows service.
sigmaWindowslow2023-03-05Windows: Service stop activity via net.exe command line
Flags Windows processes running net.exe/net1.exe with a command line containing ' stop ' to stop a service.
sigmaWindowslow2023-03-05Windows: Root Certificate Added Using certutil.exe -addstore
Flags certutil.exe executions that use -addstore with root-related parameters to install a certificate.
sigmaWindowsmedium2023-03-05Windows: Root Certificate Installation via CertMgr.EXE (/add root)
Flags CertMgr.EXE used to add a root certificate on Windows by matching /add and root in the command line.
sigmaWindowsmedium2023-03-05Windows PowerShell Set-Service StartupType Change to Disabled or Manual
Alerts on PowerShell Set-Service commands changing a service startup type to Disabled or Manual on Windows.
sigmaWindowsmedium2023-03-04Windows whoami.exe Execution With /FO CSV or Output Redirection
Detects whoami.exe runs that request CSV output or indicate output redirection for saved results.
sigmaWindowsmedium2023-02-28Windows whoami.exe Group Membership Reconnaissance via /groups Flag
Flags whoami.exe runs that use the /groups option to enumerate current user group memberships and SIDs.
sigmaWindowsmedium2023-02-28Windows sc.exe Service Security Descriptor Tampering (sdset)
Detects sc.exe executions using sdset to modify service security descriptors, enabling stealthy service tampering.
sigmaWindowsmedium2023-02-28Windows sc.exe Service Security Descriptor Changes via sdset
Alerts on sc.exe sdset activity that modifies a service security descriptor to grant access to targeted principals.
sigmaWindowshigh2023-02-28Windows Firewall Exception Rule Added for Application in Suspicious Path
Flags new Windows Defender Firewall exception rules for apps located in Temp/PerfLogs/Public/Tasks-like directories.
sigmaWindowshigh2023-02-26Windows: Mounting Internet Hosted WebDAV Shares via net.exe
Alerts on net.exe (net1.exe) commands that mount an HTTP/WebDAV network share.
sigmaWindowshigh2023-02-21Windows New Service Creation via sc.exe
Flags sc.exe service creation commands containing create and binPath on Windows, excluding Dropbox-launched cases.
sigmaWindowslow2023-02-20PowerShell Creates Windows Service via New-Service and -BinaryPathName
Flags PowerShell command lines that use New-Service with -BinaryPathName to create a Windows service.
sigmaWindowslow2023-02-20Windows Registry Persistence Indicators in Event Viewer Events.asp Links
Flags Windows registry entries that reference Event Viewer Events.asp redirection URLs, excluding known benign svchost/GPO templates.
sigmaWindowsmedium2023-02-17Windows suspicious vsstrace.dll image load by uncommon executables
Alert on vsstrace.dll module loads from processes outside common Windows/system paths.
sigmaWindowsmedium2023-02-17Windows Tomcat Log File Deletion Indicating Possible Forensic Evidence Destruction
Flags Windows file deletions matching Tomcat log paths and common Catalina/localhost access log filename patterns.
sigmaWindowsmedium2023-02-16Windows Process Command-Line Containing Unicode Right-to-Left Override (U+202E)
Alerts on Windows process launches with command lines containing Unicode U+202E to support right-to-left text obfuscation.
sigmaWindowshigh2023-02-15Windows: certutil.exe ExportPFX certificate export via -exportPFX flag
Flags certutil.exe executions on Windows that include the -exportPFX argument to export certificate material.
sigmaWindowsmedium2023-02-15Windows: certutil.EXE Downloading Files from File-Sharing Domains via Suspicious Flags
Alert when certutil.exe is run with URL/download flags targeting common file-sharing domains.
sigmaWindowshigh2023-02-15Windows certutil.exe Download from Direct IP Using URL/IP-Related Flags
Alerts when certutil.exe is launched with direct-IP download indicators and download-capable certutil flags.
sigmaWindowshigh2023-02-15