Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell: ScriptBlock using security descriptor (Win32_Trustee/Win32_Ace) and LSA data strings
Alerts on PowerShell ScriptBlock text that manipulates security descriptors and LSA-related identifiers, indicating possible persistence behavior.
sigmaWindowshigh2023-01-05Windows Registry AMSI COM Server Hijacking via InProcServer32 CLSID Modification
Alerts on registry changes that alter an AMSI COM CLSID InProcServer32 entry to break AMSI loading.
sigmaWindowshigh2023-01-04Windows PowerShell Keylogger Function Reference in Script Block Logging
Alerts on PowerShell script blocks containing keyboard IsKeyDown references associated with potential keystroke capture.
sigmaWindowsmedium2023-01-04Windows Process Creation: Suspicious Git Clone Command With Vulnerability Keywords
Flags Windows git clone commands that include exploit/vulnerability-style keywords in the process command line.
sigmaWindowsmedium2023-01-03Windows Registry EventLog Service File Location Tampering
Flags registry modifications that change the EventLog service’s configured log file location on Windows.
sigmaWindowshigh2023-01-02Windows Ruby Inline Code Execution via Ruby.exe -e Flag
Flags Windows executions of ruby.exe that include the inline code flag (-e) for direct command-line Ruby code.
sigmaWindowsmedium2023-01-02Windows Process Creation: Python Executed with the -c Inline Code Flag
Flags Windows executions of python.exe with -c inline code, excluding common installer/baseline and VS Code contexts.
sigmaWindowsmedium2023-01-02Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Alerts on Windows process launches whose command line includes well-known malicious PowerShell commandlet names.
sigmaWindowshigh2023-01-02Windows: Inline PHP execution via php.exe -r flag
Flags Windows process executions of php.exe with the inline "-r" code execution flag.
sigmaWindowsmedium2023-01-02Windows Process Creation: Perl Inline Code Execution via -e/-E
Flags command-line usage of perl.exe with inline execution (-e) on Windows process creation events.
sigmaWindowsmedium2023-01-02Windows EVTX File Creation in Non-Standard Locations
Flags creation of .evtx files outside typical Windows event log directories to support event log evasion or export.
sigmaWindowsmedium2023-01-02Windows Process Creation: Uncommon Child Processes Spawned by DefaultPack.EXE
Alerts when DefaultPack.exe spawns an uncommon child process, indicating potential proxy execution on Windows.
sigmaWindowsmedium2022-12-31Windows Image Load: coregen.exe Potential DLL Sideloading
Identifies potential DLL sideloading when coregen.exe loads DLLs outside expected system and Silverlight locations.
sigmaWindowsmedium2022-12-31Windows SharpLDAPmonitor HackTool Execution via Image Name and Credential/DC Flags
Flags SharpLDAPmonitor execution on Windows with LDAP-related command-line parameters.
sigmaWindowsmedium2022-12-30Windows: ssh.exe Used as Proxy/Local Command Launcher via ProxyCommand and LocalCommand
Detects Windows executions of ssh.exe that use ProxyCommand and PermitLocalCommand/LocalCommand to launch proxied or local commands.
sigmaWindowsmedium2022-12-29Windows: PowerShell Enable-WindowsOptionalFeature Enables Suspicious Optional Features
Alerts on PowerShell Enable-WindowsOptionalFeature used with -Online to enable listed optional features.
sigmaWindowsmedium2022-12-29Windows: Detect unregmp2.exe used to proxy-launch wmpnscfg.exe with /HideWMP
Flags Windows executions of unregmp2.exe with /HideWMP, indicating proxy-style launching behavior.
sigmaWindowsmedium2022-12-29Windows: Detect runexehelper.exe used to proxy-launch other programs
Flags process executions where runexehelper.exe is the parent, suggesting proxy-based launching of other programs.
sigmaWindowsmedium2022-12-29Windows RDP Session Hijacking via tscon.exe from System Integrity
Flags tscon.exe executions on Windows running at System integrity, indicating potential RDP session hijacking.
sigmaWindowsmedium2022-12-27Windows PowerShell Token Obfuscation via Process Command Line
Identifies Windows PowerShell command lines using token obfuscation patterns, common in Invoke-Obfuscation.
sigmaWindowshigh2022-12-27