Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: AnyDesk Password Piped via CMD Using --set-password
Alerts on Windows command lines that echo a value and set an AnyDesk password non-interactively via --set-password.
sigmaWindowsmedium2022-09-28Windows IIS connection string decryption via aspnet_regiis -pdf
Flags aspnet_regiis.exe runs that target IIS connectionStrings for decryption using -pdf.
sigmaWindowshigh2022-09-28Windows: conhost.exe spawned by uncommon parent process
Alerts on conhost.exe launched by an uncommon parent process, using process creation parent image and command-line context.
sigmaWindowsmedium2022-09-28PowerShell ScriptBlock Matching Invoke-Mimikatz Credential Dump Commands (Windows)
Detects PowerShell ScriptBlocks containing Mimikatz-like credential dump and certificate extraction command strings.
sigmaWindowshigh2022-09-28AnyDesk Windows: suspicious executable/DLL writes excluding gcapi.dll
Alerts when AnyDesk.exe or AnyDeskMSI.exe writes .dll/.exe files, excluding gcapi.dll.
sigmaWindowshigh2022-09-28Windows Process Creation: UAC bypass attempt via MMC Windows Firewall Snap-in hijack
Alerts when MMC launches WF.msc, a possible UAC bypass snap-in hijack pattern, excluding WerFault.exe-related cases.
sigmaWindowsmedium2022-09-27Windows Process Creation: SSH Port-Forwarding Commands Targeting RDP (3389)
Flags Windows command lines using SSH port-forwarding switches that also reference RDP port :3389.
sigmaWindowsmedium2022-09-27Windows ImagingDevices.exe Spawns Unusual Parent/Child Processes
Alerts when ImagingDevices.exe participates in atypical process parent/child chains on Windows, based on process creation telemetry.
sigmaWindowshigh2022-09-27Windows: Unusual Child Process Spawn by dns.exe
Alerts when dns.exe launches an unexpected child process other than conhost.exe.
sigmaWindowshigh2022-09-27Windows desktopimgdownldr.exe Remote File Download via /lockscreenurl:http
Flags desktopimgdownldr.exe executions that specify a remote lockscreen URL via /lockscreenurl:http.
sigmaWindowsmedium2022-09-27Windows Process Creation: 7-Zip Compressing .dmp/.dump Files
Flags Windows executions of 7-Zip where the command line includes .dmp/.dump/.hdmp extensions.
sigmaWindowsmedium2022-09-27Windows dns.exe Deletes Files with Unexpected Targets
Alerts when dns.exe deletes any file other than dns.log on Windows.
sigmaWindowshigh2022-09-27Windows: Unusual File Modification by dns.exe
Alert on dns.exe changing files other than dns.log, which can indicate suspicious or compromised system activity.
sigmaWindowshigh2022-09-27Windows: w32tm.exe Timer/Delay Usage via stripchart Parameters
Flags w32tm.exe executions using stripchart delay-related parameters that can support timed automation on Windows.
sigmaWindowshigh2022-09-25Windows UltraViewer Desktop App Execution
Alerts on execution of UltraViewer Desktop on Windows based on executable metadata in process creation events.
sigmaWindowsmedium2022-09-25Windows Process Creation: NetSupport Client Configurator (PCICFGUI.EXE)
Alerts on execution of NetSupport Client Configurator (PCICFGUI.EXE) on Windows via process metadata.
sigmaWindowsmedium2022-09-25Windows: Suspicious Parent Process Spawning cmd.exe
Alerts on cmd.exe executions that have a suspicious/atypical parent process among listed Windows binaries.
sigmaWindowsmedium2022-09-21Windows Process Creation: Renamed createdump.exe Used for .dmp Memory Dumps
Flags renamed createdump.exe executions on Windows that use full dump flags and produce .dmp files.
sigmaWindowshigh2022-09-20Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
sigmaWindowshigh2022-09-20PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
sigmaWindowshigh2022-09-20