Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: Renamed AutoHotkey Executable via PE Metadata
Detects renamed AutoHotkey executables by correlating process creation events with PE metadata indicators.
sigmaWindowsmedium2023-02-07Windows nltest.exe Execution for Network Information Discovery
Flags execution of nltest.exe (including nltestrk.exe via OriginalFileName) used for network and domain information discovery.
sigmaWindowslow2023-02-03Windows cmdkey.exe Adds Generic Credentials via -g Flag
Flags -g/-u/-p with cmdkey.exe indicate generic credential insertion, which can enable follow-on access.
sigmaWindowsmedium2023-02-03Windows OneNote.exe launches cmd/cscript/mshta/PowerShell/wscript with OneNote-exported scripts
Alerts when OneNote.exe spawns common script interpreters to execute OneNote-exported or offline-cache script content.
sigmaWindowshigh2023-02-02Windows: PowerShell Add-AppxPackage Attempt With -AllowUnsigned for AppX Installation
Detects PowerShell Add-AppxPackage usage with -AllowUnsigned to install unsigned AppX packages.
sigmaWindowsmedium2023-01-31Windows PowerShell: Add-AppxPackage with -AllowUnsigned for Unsigned AppX Installation
Flags PowerShell usage of Add-AppxPackage/Add-AppPackage with -AllowUnsigned to install unsigned AppX packages.
sigmaWindowsmedium2023-01-31Windows PowerShell Base64-Encoded WMI Class Invocation
Flags PowerShell command lines containing Base64 fragments indicative of WMI class usage (e.g., ShadowCopy, ScheduledJob) on Windows.
sigmaWindowshigh2023-01-30Windows Registry: Monitor PendingFileRenameOperations changes from suspicious images
Alerts on registry tampering of PendingFileRenameOperations by processes running from suspicious image paths.
sigmaWindowsmedium2023-01-27Windows WMIC System Information Discovery via WMIC.EXE Recon
Flags WMIC.EXE executions running system info queries for OS and disk details.
sigmaWindowsmedium2023-01-26Windows: Suspicious Child Process Spawned by VsCode code.exe
Alerts when code.exe spawns suspicious binaries, script hosts, or command-line activity that matches common execution patterns.
sigmaWindowsmedium2023-01-26Windows WSL Process Spawning Uncommon Child Executables
Alerts when wsl.exe or wslhost.exe spawns suspicious child binaries from common temp/public/user directories.
sigmaWindowsmedium2023-01-23Windows PowerShell Module Execution Matches Known Offensive PoshModule Script Names
Alerts on Windows PowerShell module executions where the script context matches known offensive PowerShell script/module names.
sigmaWindowshigh2023-01-23PowerShell on Windows adding Windows capabilities via Add-WindowsCapability
Alerts when PowerShell adds an OpenSSH-related Windows capability using Add-WindowsCapability.
sigmaWindowsmedium2023-01-22Windows PowerShell imports Microsoft.ActiveDirectory.Management.dll via Import-Module (AD enumeration)
Alerts when PowerShell imports Microsoft.ActiveDirectory.Management.dll using Import-Module, indicating potential AD enumeration.
sigmaWindowsmedium2023-01-22Windows IIS appcmd Creating GlobalRules URL Rewrite Configuration
Flags appcmd.exe commands that modify IIS global URL rewrite globalRules and commit the configuration.
sigmaWindowsmedium2023-01-22Windows Capability Added via PowerShell Add-WindowsCapability (OpenSSH)
Flags PowerShell commands that add Windows capabilities, specifically OpenSSH, via Add-WindowsCapability in logged script blocks.
sigmaWindowsmedium2023-01-22Windows PowerShell Active Directory Module Import for Enumeration
Detects PowerShell importing Microsoft.ActiveDirectory.Management.dll with Import-Module, often seen during AD enumeration.
sigmaWindowsmedium2023-01-22Windows PowerShell AD Module DLL Import for Active Directory Enumeration
Flags PowerShell importing Microsoft.ActiveDirectory.Management.dll via Import-Module, a common step in AD discovery and enumeration.
sigmaWindowsmedium2023-01-22Windows: Detect Aruba Netsvc DLL Search Order Hijacking via arubanetsvc.exe Loaded DLLs
Flags arubanetsvc.exe loading targeted DLLs outside standard system paths, suggesting possible DLL search order hijacking.
sigmaWindowshigh2023-01-22Windows: OneNote .one/.onepkg File Creation in Suspicious Locations
Flags creation of OneNote attachment files (.one/.onepkg) in temp/public-style paths on Windows.
sigmaWindowsmedium2023-01-22