Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Image Load: dbgcore.dll/dbghelp.dll Loaded from Uncommon User and System Paths
Alerts when dbgcore.dll or dbghelp.dll is loaded from user or other uncommon directories on Windows.
sigmaWindowshigh2025-11-27Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Flags node.exe or bun.exe spawning trufflehog/gitleaks to perform secret or credential scanning.
sigmaWindowshigh2025-11-25Windows: Suspicious Script/Command Child Processes Spawned by ArcSOC.exe
Alerts when ArcSOC.exe launches cmd/cscript/mshta/powershell/wscript and similar interpreters, indicating potential remote code execution.
sigmaWindowshigh2025-11-25ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
Alerts when ArcSOC.exe creates files with script/executable extensions such as .exe, .ps1, .aspx, or .bat.
sigmaWindowshigh2025-11-25Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Alerts when browser-launched processes include clickfix-style command markers plus tool and captcha-related terms on Windows.
sigmaWindowshigh2025-11-24Windows WSASS Process Execution via WerFaultSecure.EXE
Alerts on Windows process creation showing wsass.exe running with WerFaultSecure.exe and a PID-like argument.
sigmaWindowshigh2025-11-23Windows Process: GPME Used to Modify Default Domain and Default Domain Controllers GPOs
Flags MMC launching GPME to target Default Domain/Default Domain Controllers GPO objects by GUID via gpobject.
sigmaWindowsmedium2025-11-22Windows ImageLoad of Unsigned .node Native Add-on Files
Alerts on Windows loading of unsigned or unverifiable .node files, indicating potential native code execution in Electron-based apps.
sigmaWindowsmedium2025-11-22Windows Security Event 5136 for Changes to Default Domain and Default Domain Controllers GPOs
Flags EventID 5136 modifications to Default Domain or Default Domain Controllers GPO containers in Windows AD.
sigmaWindowsmedium2025-11-22Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.
sigmaWindowshigh2025-11-19Windows Network Connection Initiated by finger.exe
Alerts on Windows network connections started by finger.exe, an unusual utility that can support remote command retrieval.
sigmaWindowshigh2025-11-19Windows DNS Queries Triggered by finger.exe
Alerts on Windows DNS queries made by finger.exe, a rarely used utility that can be abused to fetch remote commands.
sigmaWindowshigh2025-11-19Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Flags PowerShell command lines that reference KerberosRequestorSecurityToken and .GetRequest() for suspicious Kerberos ticket requests.
sigmaWindowshigh2025-11-18Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands
Flags WMIC/PowerShell command lines that reference Win32_TerminalServiceSetting SetAllowTSConnections to change RDP.
sigmaWindowsmedium2025-11-15Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Alerts on Windows process starts of svchost.exe that include an uncommon -k parameter format, after excluding common and benign patterns.
sigmaWindowshigh2025-11-14Windows CMD for /f Tokens= with Recursive Dir Listing
Flags cmd.exe for /f loops using tokens= with recursive dir enumeration in the command line and parent.
sigmaWindowsmedium2025-11-12Windows Registry: Suspicious Space-Padded TypedPaths Details String
Alerts on registry writes to TypedPaths url1 where Details includes “#” plus unusual Unicode space padding.
sigmaWindowshigh2025-11-04Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Alerts on RunMRU registry updates containing '#' plus excessive unusual Unicode spaces that may conceal command text.
sigmaWindowshigh2025-11-04Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Alerts when Explorer spawns a process with command lines containing long Unicode whitespace padding followed by '#'.
sigmaWindowshigh2025-11-04Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Flags Windows execution of Advanced Installer PSF AI_STUBS stubs where OriginalFileName equals popupwrapper.exe.
sigmaWindowslow2025-11-03