Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Port Forwarding via SSH.EXE on Windows
Flags Windows executions of ssh.exe using remote port forwarding (-R) based on process creation command-line content.
sigmaWindowsmedium2022-10-12Windows Credential Manager Vault/File Access by Uncommon Application Images
Alerts on access to Windows credential/vault files by uncommon processes based on image path and file location.
sigmaWindowsmedium2022-10-11Windows Process Hacker Execution Identified by Image Metadata and Hashes
Alerts on Process Hacker being executed on Windows when process creation metadata or hashes match known indicators.
sigmaWindowsmedium2022-10-10Windows PowerShell Recon Using Get-LocalGroupMember on Local/Well-Known Groups
Flags PowerShell Get-LocalGroupMember usage targeting notable local group names in process creation logs.
sigmaWindowsmedium2022-10-10Windows Process Execution of PCHunter (PCHunter64.exe or PCHunter32.exe)
Flags Windows execution of PCHunter64/32.exe using image path plus PE metadata and known hashes.
sigmaWindowshigh2022-10-10Windows: NPS (npc.exe) Port Forwarding Proxy Execution via Command-Line Parameters
Flags Windows executions of npc.exe with NPS server, vkey/password, or config=npc command-line parameters.
sigmaWindowshigh2022-10-08Windows Execution of IOX (iex/port forwarding) Tunnel/Proxy Tool via Process Creation
Alerts on Windows process creation for iox.exe with tunneling/proxy forwarding command-line parameters.
sigmaWindowshigh2022-10-08Windows Process Creation: SharpWSUS or WSUSpendu Execution via PowerShell Parameters
Detects command-line execution patterns for SharpWSUS or WSUSpendu on Windows.
sigmaWindowshigh2022-10-07Windows LPE Attempt via TabTip CLSID Using Microsoft-Windows-DistributedCOM (Event ID 10001)
Alerts when TabTip.exe is started via CLSID/DCOM activation in Windows DistributedCOM EventID 10001.
sigmaWindowshigh2022-10-07Windows Process Creation: GMER Rootkit Tool Execution (gmer.exe)
Flags execution of gmer.exe on Windows when matched by known process hashes.
sigmaWindowshigh2022-10-05PowerShell PSAsyncShell Reverse Shell Activity via Script Block Logging
Detects PowerShell use of PSAsyncShell by matching the tool name in logged script block text.
sigmaWindowshigh2022-10-04Windows Driver Load of Known Vulnerable Drivers by File Name
Alerts when Windows loads a driver whose filename matches a list of known vulnerable drivers.
sigmaWindowslow2022-10-03Windows Malicious Driver Load Identified by Known Bad Driver File Names
Alerts when Windows loads a driver whose file name matches a curated list of known malicious/suspicious drivers.
sigmaWindowsmedium2022-10-03Windows Registry: Disable Privacy Settings Experience via DisablePrivacyExperience Policy
Flags Windows registry policy changes that disable the Privacy Settings Experience by setting DisablePrivacyExperience to 0x00000000.
sigmaWindowsmedium2022-10-02Windows: Process creation of UltraVNC VNCViewer (VNCViewer.exe)
Flags execution of UltraVNC VNCViewer.exe on Windows based on process creation metadata.
sigmaWindowsmedium2022-10-02Windows Registry: Modify User Shell Folders Startup Values for Persistence
Alerts on Windows Registry changes to User Shell Folders startup-related values that may be used to establish persistence.
sigmaWindowshigh2022-10-01Windows Process Creation: China Chopper Webshell Command Pattern via W3WP
Flags w3wp.exe-launched commands matching China Chopper webshell execution patterns in Windows process creation logs.
sigmaWindowshigh2022-10-01Windows Suspicious Use of shutdown.exe to Log Off a User
Flags Windows executions of shutdown.exe with /l to log a user off.
sigmaWindowsmedium2022-10-01Windows PDQ Deploy Console Execution
Alerts on Windows execution of PDQ Deploy Console (PDQDeployConsole.exe) based on process metadata.
sigmaWindowsmedium2022-10-01Windows RDP Registry Settings Modified to Zero
Alerts when RDP-related registry values are set to 0, potentially weakening remote access controls.
sigmaWindowsmedium2022-09-29