Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows AppXDeployment-Server: Unsigned MSIX/AppX installed with -AllowUnsigned
Flags Windows AppXDeployment-Server events showing unsigned MSIX/AppX installs using AllowUnsigned.
sigmaWindowsmedium2025-11-03Windows AppX/MSIX Full Trust Package Installation via AppXDeployment-Server
Flags AppX/MSIX installs with Full Trust on Windows, reducing noise by excluding common Microsoft and Program Files sources.
sigmaWindowsmedium2025-11-03Windows Registry Add WFP Filter Rules via BFE Parameters Path
Alerts on registry changes adding persistent WFP filters under the BFE policy persistent filter path via svchost.exe.
sigmaWindowsmedium2025-10-23Windows SpeechRuntime.exe Child Process Creation
Alerts when SpeechRuntime.exe spawns a child process, highlighting potential abuse for lateral movement on Windows.
sigmaWindowshigh2025-10-23Windows process creation: child process spawned by winrshost.exe
Flags Windows process children of winrshost.exe that may indicate WinRS-driven remote command execution.
sigmaWindowsmedium2025-10-22Windows Winrs.exe Local Command Execution via localhost/loopback
Alerts on Winrs.exe processes running locally by targeting localhost/loopback in /r or /remote.
sigmaWindowshigh2025-10-22Windows Suspicious File Write to Apache/Tomcat webapps ROOT (.jsp) by Web Server Processes
Alerts on .jsp writes into Apache/Tomcat webapps ROOT from dotnet/java/IIS worker processes on Windows.
sigmaWindowsmedium2025-10-20Windows: ISATAP Router Address Set via Iphlpsvc Event ID 4100
Alerts on Windows events where an ISATAP router address is set via Microsoft-Windows-Iphlpsvc, excluding localhost/null values.
sigmaWindowsmedium2025-10-19Windows SMB Server Share Connection Without Signing or Encryption
Alert on SMB share connections (IPC$/ADMIN$/C$) where signing and encryption are both reported as disabled.
sigmaWindowsmedium2025-10-19Windows: Monitor access to Signal Desktop config.json and db.sqlite in AppData\Roaming
Alerts on unauthorized access attempts to Signal Desktop’s config.json (key) and db.sqlite (messages) in the default Roaming path.
sigmaWindowsmedium2025-10-19Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Alerts when baaupdate.exe runs typical script/utility processes, an uncommon parent-child execution pattern on Windows.
sigmaWindowshigh2025-10-18Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Alerts when BaaUpdate.exe loads DLLs from Temp/Public-type locations associated with DLL search hijacking risk.
sigmaWindowshigh2025-10-18Windows Process Execution: Restic Backup Tool Command-Line Indicators
Flags Windows executions where Restic is run with repo init/backup flags or remote storage targets.
sigmaWindowshigh2025-10-17WSL Process Execution of Kali Linux on Windows
Flags Kali Linux running under WSL on Windows using process creation image and command-line indicators.
sigmaWindowshigh2025-10-10Windows WSL Kali Linux installation via wsl.exe --install -i
Flags wsl.exe commands that install a distribution specified as Kali Linux using --install -i.
sigmaWindowshigh2025-10-10Windows Registry RunMRU Key Deletion
Alerts on deletion of the Windows Run dialog command history (RunMRU) registry key.
sigmaWindowshigh2025-09-25Windows: Detect reg.exe Deletion of RunMRU Registry Key
Alerts on reg.exe commands that delete the RunMRU registry key, clearing Run dialog command history.
sigmaWindowshigh2025-09-25PUA: TruffleHog Execution on Windows via trufflehog.exe Process Launch
Flags Windows execution of trufflehog.exe, especially when targeting common code and collaboration platforms and using --results=verified.
sigmaWindowsmedium2025-09-24Windows Process Execution of EDR-Freeze Tool
Flags execution of EDR-Freeze on Windows using image-name and IMPhash matches associated with the tool.
sigmaWindowshigh2025-09-24Windows Process Creation: WerFaultSecure.exe PPL Tampering with Dump/Impair Parameters
Alerts on WerFaultSecure.exe executions with PPL-related dump/impair command-line parameters that may target sensitive security protections.
sigmaWindowshigh2025-09-23