Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Windefend: Defender Restored File from Quarantine (EventID 1009)
Alerts on Windows Defender Windefend events indicating an item was restored from quarantine (Event ID 1009).
sigmaWindowshigh2022-12-06Windows Defender SubmitSamplesConsent Disabled (Real-Time Protection)
Flags Windows Defender configuration changes disabling automatic sample submission (SubmitSamplesConsent=0x0).
sigmaWindowslow2022-12-06Windows Process Creation: Command Line Contains Emoji Characters
Alerts on Windows process executions whose command line includes emoji/symbol characters from a predefined list.
sigmaWindowshigh2022-12-05Windows Process Command Line Contains Emoji Characters
Alerts when a Windows process command line includes emoji characters, which can be used to obscure activity or bypass naive detections.
sigmaWindowshigh2022-12-05Windows Process Creation: Command Line Contains Specific Emoji Characters
Alerts when a Windows process command line includes specific emoji Unicode characters that may be used for evasion or obfuscation.
sigmaWindowshigh2022-12-05Windows Process Creation Command-Line Contains Emoji Characters
Alerts on Windows executions whose command line includes emoji Unicode characters.
sigmaWindowshigh2022-12-05Windows: Elevated PowerShell or CMD Spawned from Uncommon Parent Location
Alerts on elevated PowerShell/CMD executions whose parent process comes from uncommon Windows locations, indicating likely privilege escalation.
sigmaWindowsmedium2022-12-05Windows Process Creation: Renamed Mavinject32/64.EXE Execution
Alerts on renamed executions of mavinject32.exe/mavinject64.exe based on OriginalFileName and image path.
sigmaWindowshigh2022-12-05Windows Scheduled Task Execution of Uncommon Binaries (LOLBin Suspicion)
Alerts when a Windows Scheduled Task runs a process from a set of uncommon/suspicious binary paths.
sigmaWindowsmedium2022-12-05Windows Scheduled Task Process Run from Suspicious File Locations
Alerts on Windows Task Scheduler process creation when the executed program runs from temp, downloads, desktop, or public-writable paths.
sigmaWindowsmedium2022-12-05Windows Security: Suspicious Scheduled Task Update via Event ID 4702 Keywords
Alerts when a scheduled task is updated (EventID 4702) and the new task content includes suspicious execution keywords or temp/user paths.
sigmaWindowshigh2022-12-05Windows Security Audit: Scheduled Task Deleted or Disabled (Important Task Names)
Alerts on deletion or disabling of important Windows scheduled tasks based on Security audit events 4699 and 4701.
sigmaWindowshigh2022-12-05Windows Security: Suspicious Scheduled Task Creation via Event 4698
Alerts on Windows scheduled task creation (EventID 4698) when TaskContent contains suspicious directories or command patterns.
sigmaWindowshigh2022-12-05Windows Process Creation: SysmonEOP.exe HackTool Execution (CVE-2022-41120 PoC)
Alert on Windows process execution of \SysmonEOP.exe with specific IMPhashes associated with the SysmonEOP PoC.
sigmaWindowscritical2022-12-04Windows Process Execution of wsudo with System or TrustedInstaller
Alerts on wsudo.exe runs from wsudo-bridge.exe requesting execution as System or TrustedInstaller.
sigmaWindowshigh2022-12-02Windows DLL Sideloading: WmiApSrv Loads VMGuestLib.dll
Flags WmiApSrv.exe loading VMGuestLib.dll from VMware Tools vmStatsProvider on Windows.
sigmaWindowsmedium2022-12-01Windows DLL Sideloading via Loading ShellChromeAPI.dll
Alerts when Windows processes attempt to load ShellChromeAPI.dll, a DLL typically not present on systems.
sigmaWindowshigh2022-12-01Windows: Creation of Non-Existent System DLLs in System32 Paths
Alerts when targeted non-existent system DLL filenames are created in Windows system directories, indicating potential DLL hijacking setup.
sigmaWindowsmedium2022-12-01Windows: Gpg4win (GnuPG) Encrypt/Decrypt Command Using Suspicious File Paths
Flags Gpg4win/GnuPG file crypto commands using -passphrase with activity in temporary/public or suspicious Windows directories.
sigmaWindowshigh2022-11-30Windows PowerTool Process Execution
Flags Windows process creation events where PowerTool.exe/PowerTool64.exe is launched.
sigmaWindowshigh2022-11-29