Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows LSA event: Standard user SID in privileged AD groups (EventID 300)
Alerts when LSA Event 300 shows a standard user interacting with high-privileged group SIDs, excluding common domain admin patterns.
sigmaWindowsmedium2023-01-13Windows Registry change enabling developer features for sideloading and untrusted app installs
Alerts on registry writes that enable Windows developer feature policies allowing sideloading of untrusted apps.
sigmaWindowshigh2023-01-12Windows process creation: Suspicious child processes from WindowsApps directory
Alerts on suspicious cmd/PowerShell/mshta/rundll32-style child processes launched from Program Files\WindowsApps.
sigmaWindowsmedium2023-01-12Windows SRP restricted application access (Event IDs 865, 866, 867, 868, 882)
Flags Windows SRP enforcement events where attempts to access applications are restricted by administrator policy.
sigmaWindowshigh2023-01-12Windows Registry PowerShell ExecutionPolicy Tampering (Bypass/Unrestricted)
Alerts on Windows registry changes that set PowerShell ExecutionPolicy to Bypass or Unrestricted.
sigmaWindowsmedium2023-01-11Windows process activity enabling Developer Mode or sideloading via SystemSettingsAdminFlows.exe
Alerts on SystemSettingsAdminFlows.exe command lines enabling Developer Mode unlock or application sideloading.
sigmaWindowshigh2023-01-11Windows Process Creation: PowerShell Execution Policy Registry Tampering via CommandLine
Alerts when a process command line references PowerShell ExecutionPolicy registry paths and weaker policy values.
sigmaWindowshigh2023-01-11Windows BITS Client Job Downloads from Direct IP Addresses
Alerts when Windows BITS Client downloads via HTTP/HTTPS URLs containing direct IP addresses.
sigmaWindowshigh2023-01-11Windows AppX Deployment: Uncommon Appx Path Added to Deployment Pipeline
Alerts when an AppX package is queued for processing from uncommon paths or URLs in Windows AppX deployment server events.
sigmaWindowsmedium2023-01-11Windows AppX Deployment Blocked by Local Policy
Detects blocked AppX package deployments on Windows via AppXDeployment-Server policy-denial Event IDs.
sigmaWindowsmedium2023-01-11Windows AppX Package Deployment: Suspicious AppX Installation Attempts by PackageFullName
Alerts on Windows AppX deployment events tied to a known-malicious AppX package identifier.
sigmaWindowsmedium2023-01-11Windows AppX Deployment: Staged Directory Package Added to Pipeline
Alerts when AppX deployment processing references a package located in typical staging directories such as Temp or Downloads.
sigmaWindowshigh2023-01-11Windows AppX Deployment Failure (0x80073cff) Due to Signing Requirements
Alerts on Windows AppX deployments/installations failing with 0x80073cff, consistent with unmet signing requirements.
sigmaWindowsmedium2023-01-11Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
sigmaWindowshigh2023-01-11Windows AppX deployment blocked by AppLocker (AppXDeployment-Server EventID 412)
Flags AppX package deployment attempts that AppLocker blocked, based on AppXDeployment-Server EventID 412.
sigmaWindowsmedium2023-01-11Windows Process Creation: PowerShell Import-Module from Temp/AppData/Public Paths
Alerts on PowerShell Import-Module calls that load modules from Temp, AppData, or Public directories on Windows.
sigmaWindowsmedium2023-01-10PowerShell script alias obfuscation via -Value (-join(...))
Flags PowerShell script blocks that set aliases using -Value with a (-join(...)) character-joining obfuscation pattern.
sigmaWindowslow2023-01-09Windows PowerShell Script Block Alerts for Set-Alias and New-Alias Usage
Alerts on PowerShell scripts that create aliases via Set-Alias/New-Alias, a common obfuscation technique, using ScriptBlockText logging.
sigmaWindowslow2023-01-08Windows Suspicious Double-Extension Execution via Parent Command Line
Alerts on Windows processes launched by parents whose image/command line includes disguised double-extension tokens.
sigmaWindowshigh2023-01-06Windows PowerShell Process Creation: Suspicious Base64/Encoded and IEX WebClient Patterns
Detects suspicious PowerShell process command lines using hidden/no-profile, execution-policy bypass, and encoded/Base64 or IEX WebClient download patterns.
sigmaWindowsmedium2023-01-05