Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
Detects rundll32 executions that reference DLLs stored in Alternate Data Streams via ADS-style paths.
sigmaWindowshigh2023-01-21Windows PsExec Remote Execution Creates PSEXEC-*.key File Artefact
Alerts on creation of PsExec key files in C:\Windows\PSEXEC-*.key, indicating remote execution activity.
sigmaWindowshigh2023-01-21Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Alerts on PowerShell module payloads containing commandlet/function names from known malicious exploitation and post-exploitation frameworks.
sigmaWindowshigh2023-01-20Windows driverquery.exe Process Execution Detection
Alerts on Windows executions of driverquery.exe (drvqry.exe) used to enumerate installed drivers, with parent-process exclusions to reduce duplicates.
sigmaWindowsmedium2023-01-19Windows: driverquery.exe Usage for Installed Driver Recon
Alerts when driverquery.exe (drvqry.exe) is launched by script-based parent processes to enumerate installed drivers.
sigmaWindowshigh2023-01-19Windows Successful SMB Logon (Event ID 4624 Logon Type 3) From Public IPs
Flags successful Windows SMB (LogonType 3) logons from non-private, non-local source IP addresses.
sigmaWindowshigh2023-01-19Windows RDP Successful Logon (4624 LogonType 10) from Public IP
Alerts on successful RDP (LogonType 10) from a non-private, non-local source IP in Windows Security Event 4624.
sigmaWindowsmedium2023-01-19Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
sigmaWindowshigh2023-01-18Windows Firewall Rules Deleted (Windows Defender Firewall) via Firewall-as Events
Alerts on Windows Defender Firewall configurations where all rules are deleted (Event 2033/2059), signaling potential defense impairment.
sigmaWindowshigh2023-01-17PowerShell Data Exfiltration Using Audio File (WAV BinaryWriter) on Windows
Alerts on PowerShell script blocks that appear to write data into an audio (WAV) file for potential exfiltration.
sigmaWindowsmedium2023-01-16Windows DNS Client: DNS queries containing "ufile.io"
Alerts on Windows DNS Client queries where the queried name includes "ufile.io".
sigmaWindowslow2023-01-16Windows DNS Client: MEGA userstorage subdomain DNS query (EventID 3008)
Detects Windows DNS client queries for MEGA userstorage subdomains by matching the query name string.
sigmaWindowsmedium2023-01-16Windows DNS Client: Cobalt Strike DNS Beaconing Patterns via Suspicious Query Names
Alerts when Windows DNS client logs show Event ID 3008 DNS queries matching Cobalt Strike beacon patterns.
sigmaWindowscritical2023-01-16Windows DNS Client: DNS query for anonfiles.com domain
Alerts when Windows DNS client logs show a DNS query containing .anonfiles.com.
sigmaWindowshigh2023-01-16Windows AppX Packaging: Execute AppX with Suspicious Digital Signature Certificate
Alerts when AppX package execution/signature subject matches a known suspicious certificate in Windows telemetry.
sigmaWindowsmedium2023-01-16Windows AppX Execution of Sysinternals Tools (procdump/psloglist/psexec/livekd/ADExplorer)
Flags execution of common Sysinternals binaries when launched through the Windows AppX runtime.
sigmaWindowslow2023-01-16Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence
Flags registry writes that reference an Excel XLL add-in via a '/R ' command under Excel Options.
sigmaWindowshigh2023-01-15Windows Registry: DisableRestrictedAdmin Value Tampering to Change Restricted Admin Mode
Flags registry modifications to DisableRestrictedAdmin that change Restricted Admin mode settings.
sigmaWindowshigh2023-01-13Windows Process Creation: Registry Tampering of DisableRestrictedAdmin in Lsa Key
Alerts when a process command line references LSA DisableRestrictedAdmin to change RestrictedAdmin behavior via the registry.
sigmaWindowshigh2023-01-13Windows Task Scheduler: Detects Scheduled Task Deletion or Disabling (Task Deleted/Disabled)
Alert on deletion or disabling of targeted Windows scheduled tasks tied to system, security, and update components.
sigmaWindowshigh2023-01-13