Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows certutil.exe Used to Download Files via Suspicious Command-Line Flags
Alerts on certutil.exe runs with URL/HTTP-related flags indicative of remote file download.
sigmaWindowsmedium2023-02-15Windows certutil.exe Base64/Hex Decode via -decode or -decodehex Flags
Flags certutil.exe use for decoding base64 or hex data via -decode or -decodehex on Windows.
sigmaWindowshigh2023-02-15Windows: CertOC.exe Loading a DLL from User-Writable Paths via -LoadDLL
Alerts on CertOC.exe using -LoadDLL with DLLs from temp/user-writable directories on Windows.
sigmaWindowshigh2023-02-15Windows PowerShell Console History File Deleted (PSReadLine)
Flags deletion of the PowerShell PSReadLine ConsoleHost_history.txt file, which can remove command history evidence.
sigmaWindowsmedium2023-02-15Windows Event Log EVTX File Deletion in winevt\Logs
Flags deletion of Windows Event Log .evtx files under System32\winevt\Logs.
sigmaWindowsmedium2023-02-15Windows WMIC Remote Query Execution via /node
Identifies remote WMIC queries on Windows by matching WMIC execution with /node: in the command line.
sigmaWindowsmedium2023-02-14Windows WMIC.exe Service Reconnaissance via Remote Service Queries
Flags WMIC.exe commands containing service-related reconnaissance strings while excluding stop/start service manipulation.
sigmaWindowsmedium2023-02-14Windows WMIC.exe Product Class Reconnaissance via Security Product Queries
Detects wmic.exe being used to enumerate firewall, antivirus, and antispyware product classes.
sigmaWindowsmedium2023-02-14Windows WMIC Product Reconnaissance via Firewall/AV Enumeration
Alerts on wmic.exe executions with command lines consistent with Windows product enumeration for reconnaissance.
sigmaWindowsmedium2023-02-14Windows wmic.exe Hardware Model Reconnaissance Using csproduct
Flags wmic.exe executions that include "csproduct" to query hardware model/vendor details.
sigmaWindowsmedium2023-02-14Windows execution of LocalPotato POC (LocalPotato.exe with specific PE/CLI traits)
Detects LocalPotato.exe process execution on Windows using image path, typical CLI parameters, and known imphash values.
sigmaWindowshigh2023-02-14Windows Suspicious Execution of Regasm/Regsvcs With Uncommon Command-Line Extension
Flags Regasm.exe/Regsvcs.exe runs that include unusual extensions in the command line, which may indicate stealthy misuse.
sigmaWindowsmedium2023-02-13Windows: Filter Driver Unload via fltMC.exe
Flags fltMC.exe executions that include "unload" to indicate potential filter driver unloading for defense impairment.
sigmaWindowsmedium2023-02-13Windows: Suspicious Executable Created in Temp by OneNote (onenote.exe/onenotem.exe/onenoteim.exe)
Alerts when OneNote creates files in Temp\OneNote with script/executable extensions on Windows.
sigmaWindowshigh2023-02-09Windows Registry: Outlook EnableUnsafeClientMailRules Set to 1
Alerts when Outlook’s EnableUnsafeClientMailRules registry value is enabled (DWORD 0x1), reducing mailbox macro/script protections.
sigmaWindowshigh2023-02-08Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
Alerts on Windows executions referencing gatherNetworkInfo.vbs in process command lines, indicative of potential discovery activity.
sigmaWindowshigh2023-02-08Windows: Outlook loads outlvba.dll (VBA for Outlook add-in) via image loading
Alerts on outlvba.dll being loaded by outlook.exe, indicating VBA add-in execution within Outlook.
sigmaWindowsmedium2023-02-08Windows: .pub File Creation in Temp or Public Directories
Alerts on creation of .pub files in Temp/Public-like directories on Windows where staging is likely.
sigmaWindowsmedium2023-02-08Windows: Suspicious Outlook VbaProject.OTM Macro File Created
High-confidence file creation alert for Microsoft\Outlook\VbaProject.OTM while excluding outlook.exe.
sigmaWindowshigh2023-02-08Windows File Events: VBS gatherNetworkInfo results file creation
Flags Windows file writes under System32\config consistent with gatherNetworkInfo.vbs network reconnaissance output.
sigmaWindowsmedium2023-02-08