Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Executable Initiating Connections to ngrok Tunnel Domains
Flags Windows network connections to ngrok tunnel subdomains that may indicate tunneling for C2 or staging.
sigmaWindowshigh2022-11-03Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
sigmaWindowshigh2022-11-01Windows Scheduled Task Creation with GUID-like Task Name
Alerts on schtasks.exe creating scheduled tasks whose /TN value is wrapped GUID-like braces.
sigmaWindowsmedium2022-10-31Windows Image Load: Uncommon VSSAPI DLL (vssapi.dll) by Suspicious Executables
Alerts when uncommon processes load vssapi.dll, a Shadow Copy–related DLL, using image load telemetry with path-based exclusions.
sigmaWindowshigh2022-10-31Windows Remote Utilities Host Service Installation via Service Control Manager (EventID 7045)
Alerts on Windows Event 7045 when a "Remote Utilities - Host" service is installed from rutserv.exe -service.
sigmaWindowsmedium2022-10-31Windows Service Installation via NetSupport Manager (Event ID 7045)
Flags Windows service creation for NetSupport Manager Client32 (client32.exe) using Service Control Manager Event ID 7045.
sigmaWindowsmedium2022-10-31Windows: vsls-agent.exe Executed With --agentExtensionPath Suspicious Library Load
Flags vsls-agent.exe launched with --agentExtensionPath, suggesting a potentially suspicious external extension/library load.
sigmaWindowsmedium2022-10-30Windows Named Pipe Creation: PAExec Default Pipe (\PAExec*)
Alerts on named pipe creations starting with "\PAExec" associated with PAExec default behavior on Windows.
sigmaWindowsmedium2022-10-26Windows Exchange PowerShell Cmdlet History Log Files Deleted
Flags deletion of Exchange PowerShell cmdlet history log files in the expected logging directory.
sigmaWindowshigh2022-10-26Windows Service Control Manager: Detect PAExec- service installation
Flags creation of PAExec-named Windows services with image paths under C:\WINDOWS via Event ID 7045.
sigmaWindowsmedium2022-10-26Windows: Registry change disabling MacroRuntimeScanScope runtime macro scanning
Flags Office registry updates that set MacroRuntimeScanScope to 0x00000000, disabling runtime scanning for enabled macros.
sigmaWindowshigh2022-10-25Windows CLI Searching for JWT Strings (eyJ0eX / eyJhbGci) in Command Line
Flags Windows CLI token hunting when search utilities are used alongside JWT-like substrings in the command line.
sigmaWindowsmedium2022-10-25Windows Image Load: Suspicious DLL Sideloading of dbghelp.dll
Alerts on dbghelp.dll being loaded from non-standard locations, indicating possible DLL sideloading.
sigmaWindowsmedium2022-10-25Windows Image Load Alerts for dbgcore.dll Sideloading
Alerts when dbgcore.dll is loaded from paths outside typical Windows directories, indicating possible DLL sideloading.
sigmaWindowsmedium2022-10-25OpenSSH Server (sshd) Listening on SSH Socket on Windows
Flags OpenSSH (sshd) events showing the SSH server has started listening on a socket.
sigmaWindowsmedium2022-10-25Inveigh Execution via Process Creation (Windows)
Detects execution of Inveigh.exe on Windows with spoofing/sniffing command-line flags consistent with MITM behavior.
sigmaWindowscritical2022-10-24PowerShell: Suspicious Set-Service DACL/SecurityDescriptor Modification for Hidden Services
Flags PowerShell ScriptBlock activity using Set-Service with specific SDDL elements consistent with hiding services from tools like sc.exe.
sigmaWindowshigh2022-10-24Windows Inveigh HackTool Execution Artefacts via Inveigh File Indicators
Alert on Windows file creation or presence of Inveigh log, script, and binary artefacts identified by distinctive filename suffixes.
sigmaWindowscritical2022-10-24Windows MsiInstaller installs remote MSI from web URLs (EventID 1040/1042)
Flags Windows Installer MsiInstaller events that indicate downloading and installing an MSI from a URL.
sigmaWindowsmedium2022-10-23Windows Alternate Data Stream Creation: Suspicious Zone.Identifier ADS Outside Browser Download
Flags suspicious creation of :Zone.Identifier ADS streams (ZoneTransfer/ZoneId=3) on file types outside typical browsers.
sigmaWindowsmedium2022-10-22