Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
SharpImpersonation Tool Execution on Windows
Flags execution of SharpImpersonation.exe on Windows when command-line parameters indicate token impersonation activity.
sigmaWindowshigh2022-12-27Windows: Execution of Htran/NATBypass HackTool Binaries or Tran/Slave CLI Flags
Detects Windows executions of htran.exe or lcx.exe and command lines containing -tran or -slave flags.
sigmaWindowshigh2022-12-27Windows PowerShell Inline Execution via File Reads and Raw Parameters
Alerts on PowerShell command lines that inline-execute content read from files using -raw.
sigmaWindowsmedium2022-12-25Windows Process Creation: PowerShell COM CLSID Download Cradles
Alerts on PowerShell command lines using GetTypeFromCLSID with selected CLSIDs that may be used to download files via COM.
sigmaWindowsmedium2022-12-25PowerShell ScriptBlock COM CLSID GetTypeFromCLSID Download Cradle Indicators
Alerts on PowerShell script blocks using GetTypeFromCLSID with specific CLSIDs indicative of COM-based download cradles.
sigmaWindowsmedium2022-12-25Windows PowerShell: In-Memory Assembly Loading via Reflection.Assembly
Flags PowerShell script blocks that reference [Reflection.Assembly]::load for potential in-memory assembly loading.
sigmaWindowsmedium2022-12-25Windows Process Execution: Suspicious AgentExecutor.exe PowerShell Launch with ExecutionPolicy Bypass
Detects AgentExecutor.exe command lines that trigger PowerShell script execution, including remediations and potentially bypassed ExecutionPolicy.
sigmaWindowshigh2022-12-24Windows AgentExecutor.exe PowerShell Execution (ExecutionPolicy Bypass) Process Creation
Alerts on AgentExecutor.exe launches that pass -powershell/-remediationScript to run PowerShell (including bypass execution policy).
sigmaWindowsmedium2022-12-24Windows Process Copy/Move of Browser Credential Stores
Identifies Windows commands copying or moving browser user data directories consistent with credential theft.
sigmaWindowsmedium2022-12-23Windows Process Creation: Suspicious X509Enrollment.CBinaryConverter Execution
Alerts on Windows command lines referencing X509Enrollment.CBinaryConverter with a specific GUID.
sigmaWindowsmedium2022-12-23PowerShell FromBase64String Decoding of Base64 Gzip Content in Process Creation on Windows
Windows process command lines using PowerShell FromBase64String with MemoryStream and Gzip-like Base64 markers (H4sI) are flagged.
sigmaWindowsmedium2022-12-23Windows PowerShell Execution of AADInternals Cmdlets (process creation)
Flags PowerShell processes running AADInternals “-AADInt” cmdlets, indicating potential Azure AD/Office 365 administration or abuse.
sigmaWindowshigh2022-12-23Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Alerts on Windows launches of Chromium-based browsers in headless + remote debugging mode targeting a user data directory.
sigmaWindowshigh2022-12-23Suspicious X509Enrollment usage in Windows PowerShell scripts
Alerts on PowerShell script blocks containing X509Enrollment.CBinaryConverter and a specific enrollment GUID.
sigmaWindowsmedium2022-12-23PowerShell: FromBase64String Decoding of Gzip (H4sI) into MemoryStream
Identifies PowerShell script blocks that base64-decode and Gzip-unpack embedded content using in-memory streams.
sigmaWindowsmedium2022-12-23Windows PowerShell Script Block Logging: AADInternals Cmdlets (Add-AADInt to Update-AADInt) Execution
Flags PowerShell script block execution that contains AADInternals cmdlet names (AADInt), indicating potential admin or abuse activity.
sigmaWindowshigh2022-12-23Windows System Service Installation of Remote Access Tool Services (Event 7045/7036)
Flags Windows service installation or updates for remote access tool services using Service Control Manager events.
sigmaWindowsmedium2022-12-23Windows Security Event 4697 Service Install of Remote Access Tools
Alerts on Windows service creation (EID 4697) where the service name matches known remote access tool indicators.
sigmaWindowsmedium2022-12-23Windows: Explorer opened from cmd.exe/powershell using shell:MyComputerFolder shortcut
Flags explorer.exe opened for My Computer via shell:mycomputerfolder when started by cmd or PowerShell.
sigmaWindowshigh2022-12-22Windows Process Creation: Impersonate.exe HackTool Execution
Flags execution of impersonate.exe (Impersonate tool) on Windows using command-line subcommands or known hashes.
sigmaWindowsmedium2022-12-21