Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry Set Detection of Suspicious Environment Variable Commands
Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.
sigmaWindowshigh2022-12-20Windows Office Binary Execution with Renamed Image Path
Alerts when Office apps are executed under renamed or unexpected image paths, helping catch stealthy masquerading on Windows.
sigmaWindowshigh2022-12-20Windows SQLite CLI Querying Chromium Browser Profile Databases
Alerts when SQLite CLI is used to query Chromium-based browser profile databases containing logins, cookies, or history.
sigmaWindowshigh2022-12-19Windows DLL Sideloading via comctl32.dll in .local directories
Alerts on comctl32.dll loaded from System32 .local folders, consistent with Windows DLL sideloading.
sigmaWindowshigh2022-12-16Windows File Events: Suspicious .exe.local Path With comctl32.dll in System32
Detects System32 *.exe.local entries that reference comctl32.dll, consistent with DLL sideloading behavior.
sigmaWindowshigh2022-12-16Windows DLL Sideloading Indicator: JsSchHlp Loads JSESPR.dll from Untrusted Path
Alerts on unexpected loads of \JSESPR.dll, indicating possible DLL sideloading outside the Justsystem JsSchHlp directory.
sigmaWindowsmedium2022-12-14Windows DLL Sideloading: ClassicExplorer32.dll Loaded from Unexpected Path
Alerts when ClassicExplorer32.dll is loaded from unexpected locations, suggesting possible DLL sideloading behavior.
sigmaWindowsmedium2022-12-13Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Alerts on registry changes to Windows legal notice caption/text containing ransomware-style keywords.
sigmaWindowshigh2022-12-11Windows: Alert on Unusual Child Process of Setres.EXE Spawning 'choice' Executables
Identifies uncommon setres.exe children matching '\choice' while excluding System32/SysWOW64 choice.exe.
sigmaWindowshigh2022-12-11Windows: Detect rcedit editing PE version/resource metadata via --set-*
Alerts on rcedit command-line usage that sets PE metadata fields to alter executable file properties.
sigmaWindowsmedium2022-12-11Windows Privilege Escalation via mklink Symlink Between cmd.exe and osk.exe
Alerts on mklink creating a symlink between osk.exe and cmd.exe, enabling potential login-screen privilege escalation.
sigmaWindowshigh2022-12-11Windows PowerShell nslookup DNS TXT Download Cradle
Identifies PowerShell launching an nslookup-based cradle that queries TXT records with HTTP-related nslookup parameters.
sigmaWindowsmedium2022-12-10Windows ETW Logging Disabled via SCM Registry TracingDisabled Key
Detects SCM ETW logging being disabled by setting the TracingDisabled registry DWORD for services.exe.
sigmaWindowslow2022-12-09Windows Registry Change Disables ETW for rpcrt4.dll via ExtErrorInformation
Flags Windows registry updates that disable ETW logging for rpcrt4.dll through ExtErrorInformation.
sigmaWindowslow2022-12-09Windows Process Creation: conhost.exe with High IntegrityLevel and -ForceV1
Flags conhost.exe started with -ForceV1 from a High integrity process on Windows.
sigmaWindowsinformational2022-12-09Windows Image Load of Specific System DLLs Not Normally Present in System Directories
Alerts on image load events for specific system-path DLLs with unexpected “phantom” DLL names on Windows.
sigmaWindowshigh2022-12-09Windows Registry: LSASS Full Dump via WER LocalDumps DumpType=2
Flags registry changes enabling LSASS full memory dumps by setting WER LocalDumps DumpType to 0x2.
sigmaWindowshigh2022-12-08Windows: LSASS Dump (.dmp) Files in CrashDumps Folder
Alerts when an lsass.exe dump (.dmp) appears in the Windows CrashDumps directory under systemprofile.
sigmaWindowshigh2022-12-08Windows Application Error: LSASS (lsass.exe) Crashed (Event ID 1000)
Alerts on Application Error (Event ID 1000) entries where lsass.exe crashes, using Windows Application event telemetry.
sigmaWindowshigh2022-12-07Windows windefend alerts on suspicious Windows Defender configuration changes (Disable* and SpyNet reporting)
Alerts on windefend Event 5007 when Defender configuration changes set features like anti-spyware, scanning, or SpyNet reporting to disabled values.
sigmaWindowshigh2022-12-06