Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: Suspicious Child Processes Spawned by Electron Apps
Flags suspicious command/scripting child processes launched by Electron apps such as Teams, Discord, Slack, and Edge.
sigmaWindowsmedium2022-10-21Suspicious Process Execution by Microsoft OneNote on Windows Child Programs
Alerts when onenote.exe spawns suspicious script or system execution child processes on Windows, consistent with malicious OneNote payload behavior.
sigmaWindowshigh2022-10-21Windows DLL Search Order Hijacking: Suspicious DLL Writes to App Dependency Folders
Alerts on suspicious .dll file creation by Office/cmd/scripting processes in AppData and OneDrive/Teams/Slack/VS Code directories.
sigmaWindowsmedium2022-10-21Windows Process Execution: SafetyKatz HackTool (SafetyKatz.exe)
Alerts when a process running SafetyKatz.exe is created, using image path and embedded file metadata.
sigmaWindowscritical2022-10-20Windows Process Creation: Seatbelt.exe PUA Discovery Command-Line Execution
Alerts on Windows process launches of Seatbelt.exe with discovery group arguments and outputfile usage.
sigmaWindowshigh2022-10-18PowerShell Set-Acl targeting Windows folder paths on Windows
Flags PowerShell Set-Acl commands that modify ACLs for Windows folder paths, often using FullControl/Allow.
sigmaWindowshigh2022-10-18PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.
sigmaWindowshigh2022-10-18PowerShell Set-Service SecurityDescriptorSddl DACL Modification for Windows Services
Detects PowerShell Set-Service commands with SecurityDescriptorSddl SDDL patterns that modify Windows service DACLs.
sigmaWindowshigh2022-10-18Windows PowerShell Set-Service SDDL Usage to Hide Services
Flags pwsh Set-Service commands that set a SecurityDescriptorSddl to hide a Windows service from other tools.
sigmaWindowshigh2022-10-17PowerShell Set-Service SecurityDescriptor (DCLCWPDTSD) to Hide Services
Flags PowerShell Set-Service calls that set a SecurityDescriptor SDDL (DCLCWPDTSD) to hide services from other utilities.
sigmaWindowshigh2022-10-17Uncommon Applications Access Windows DPAPI Master Key Files
Alerts on unusual process access to Windows DPAPI master key files under Microsoft\Protect.
sigmaWindowsmedium2022-10-17Windows Credential History File Access by Uncommon Applications
Alerts on CREDHIST file access from unexpected application images, indicating potential credential history theft.
sigmaWindowsmedium2022-10-17Windows Security Event 5136: msDS-KeyCredentialLink Shadow Credential Added to AD Object
Alerts on AD attribute changes adding to msDS-KeyCredentialLink via Windows Security EventID 5136, consistent with shadow credential additions.
sigmaWindowshigh2022-10-17Windows process execution: wermgr.exe running outside standard system directories
Alerts when wermgr.exe is launched from a non-standard directory on Windows.
sigmaWindowshigh2022-10-14Windows Process Creation: Suspicious Child Process Spawned by Wermgr.EXE
Alerts on suspicious children spawned by wermgr.exe using common execution utilities, with a rundll32 WerConCpl exclusion.
sigmaWindowshigh2022-10-14Windows Security Logoff Events (Event ID 4634/4647)
Identifies Windows user logoff using Security Event IDs 4634 and 4647.
sigmaWindowsinformational2022-10-14Windows Kerberos Replay Attack Likely Activity on Domain Controllers (Event ID 4649)
Alerts on Windows Security Event 4649 indicating a Kerberos replay error (KRB_AP_ERR_REPEAT).
sigmaWindowshigh2022-10-14Windows Security Event 6423: Device Installation Blocked by Policy
Alerts when Windows blocks a device installation due to enforced system policy (Event ID 6423).
sigmaWindowsmedium2022-10-14Windows Security Event Add/Remove Computer Account (4741/4743)
Alerts on Windows domain computer account create/delete activity via Security event 4741 and 4743.
sigmaWindowslow2022-10-14Windows: ssh.exe RDP tunneling to :3389 via SSH
Alerts on Windows process executions of ssh.exe that reference RDP port :3389 for SSH tunneling.
sigmaWindowshigh2022-10-12