Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Service Installation: TacticalRMM Agent Service (SCM Event 7045)
Flags Windows service installations that include tacticalrmm.exe and the TacticalRMM Agent Service using SCM Event ID 7045.
sigmaWindowsmedium2022-11-28Windows Service Control Manager: Mesh Agent Service Installation via Service Creation (7045)
Flags Windows Event ID 7045 service installations that reference MeshAgent.exe or “Mesh Agent”.
sigmaWindowsmedium2022-11-28Windows UAC Bypass via Event Viewer RecentViews Path in Process Command Line
Flags Windows processes whose command lines reference Event Viewer RecentViews and use redirection, consistent with UAC bypass techniques.
sigmaWindowshigh2022-11-22Windows Registry NGenAssemblyUsageLog Key Tampering via .NET Usage Log Configuration
Alerts on registry modifications to the .NETFramework NGenAssemblyUsageLog key that can disrupt .NET Usage Log creation.
sigmaWindowshigh2022-11-18Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Flags secedit.exe command lines used to export or configure Windows security policy.
sigmaWindowsmedium2022-11-18Windows: Suspicious Powercfg Execution Changing Lock/Video Standby Timeout
Detects powercfg.exe commands attempting to change standby/lock-related timeouts on Windows.
sigmaWindowsmedium2022-11-18Windows: Suspicious Msbuild.exe execution from uncommon parent process
Alerts when Msbuild.exe runs under an unexpected parent process on Windows.
sigmaWindowsmedium2022-11-17PowerShell Get-ADUser User Discovery and Data Export via File Output
Detects PowerShell Get-ADUser-based user enumeration combined with exporting results to files or output streams.
sigmaWindowsmedium2022-11-17PowerShell Get-ADComputer Cmdlet Used for Computer Discovery and File Export
Flags PowerShell Get-ADComputer wildcard enumeration followed by writing exported computer data to a file.
sigmaWindowsmedium2022-11-17Windows file activity matching CrackMapExec/Impacket-secretsdump credential dumping temp output patterns
Alerts on Windows temp file creations consistent with CrackMapExec or Impacket-secretsdump credential dumping activity.
sigmaWindowshigh2022-11-16Windows Driver Load: Process Hacker (processhacker.sys) Presence
Flags Windows driver loads of Process Hacker’s processhacker.sys using path and known imphash indicators.
sigmaWindowshigh2022-11-16Windows Process Creation: Suspicious RunAs-Like Command-Line Flag Combination
Flags Windows processes with both target-user and target-command flags in the same command line.
sigmaWindowsmedium2022-11-11PowerShell Get-ADComputer Export of Active Directory Computer Data to File (Windows)
Detects PowerShell running Get-ADComputer (* filter) and exporting results to a file via output/content cmdlets.
sigmaWindowsmedium2022-11-10Windows: Detect sftp.exe used as a LOLBIN via -D option
Alerts on Windows executions of sftp.exe using the -D flag with a path argument.
sigmaWindowsmedium2022-11-10Windows Code Integrity blocked image/driver loads due to signature level or policy violations
Alerts on Windows Code Integrity Event ID 3077 when an image/driver load is blocked for signing-level or policy violations.
sigmaWindowshigh2022-11-10PowerShell AMSI Bypass Assembly GetType Pattern in Script Block Text
Flags PowerShell scripts containing a reflection-based AMSI bypass fragment with GetType and SetValue($null,$true).
sigmaWindowshigh2022-11-09Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
Flags appcmd.exe executions that include password-related listing parameters for IIS service account credentials.
sigmaWindowshigh2022-11-08Windows File Creation: Suspicious LNK Double-Extension Targeted by Document/Image Prefixes
Alerts on Windows-created filenames that end in .lnk while containing hidden-looking double extensions (e.g., .doc. .pdf.)
sigmaWindowsmedium2022-11-07Windows Security 4624 LogonType 9 Impersonation via Negotiate (Advapi) Token Abuse Indicator
Identifies Windows successful logons consistent with potential access token impersonation using Advapi and Negotiate.
sigmaWindowsmedium2022-11-06Windows process creation: suspicious ping wait followed by del file deletion
Flags cmd/powershell command lines that use ping -n with Nul redirection followed by Del /f /q to delete a file.
sigmaWindowshigh2022-11-03