Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: Remote Utilities renamed to rutserv.exe or rfusclient.exe
Alerts on suspicious Windows execution tied to "Remote Utilities" where the image does not match known rutserv.exe/rfusclient.exe names.
sigmaWindowsmedium2022-09-19Windows: Detects NetSupport RAT client32.exe execution using Imphash and filename metadata
Flags renamed NetSupport RAT client32.exe launches on Windows using a specific Imphash and file metadata, while filtering a matching image path.
sigmaWindowshigh2022-09-19Windows: RURAT (Remote Utilities) Executed From Unusual Path
Alerts on Remote Utilities RURAT executables running outside the typical Program Files install paths on Windows.
sigmaWindowsmedium2022-09-19Windows: NetSupport client32.exe Executed From Non-Standard Directory
Flags NetSupport client32.exe launched from locations outside Program Files on Windows.
sigmaWindowsmedium2022-09-19Windows: Detect winPEAS privilege escalation reconnaissance execution
Flags Windows executions of winPEAS/PEASS-ng based on image name and command-line discovery options and release download indicators.
sigmaWindowshigh2022-09-19Windows Registry: Tampering ChannelAccess Permissions for WINEVT Event Channels
Alerts on registry updates to WINEVT ChannelAccess that set SDDL permissions granting elevated access to event channels.
sigmaWindowshigh2022-09-17Windows Process Creation: Command Line Targets Microsoft Teams Cookies or LevelDB
Alerts when non-Teams processes reference Microsoft Teams Cookies or Local Storage leveldb paths in their command line.
sigmaWindowsmedium2022-09-16PowerShell Adds Windows Defender Exclusions via Add-MpPreference/Set-MpPreference
Flags PowerShell commands that add Windows Defender exclusions using Add-MpPreference/Set-MpPreference with exclusion parameters.
sigmaWindowsmedium2022-09-16Windows PowerShell Sensitive File Discovery via ScriptBlock Enumeration
PowerShell script blocks using recursive file enumeration that target sensitive file extensions.
sigmaWindowsmedium2022-09-16Windows IIS WebServer Access Log Files Deleted
Alerts when IIS access log files (.log) under inetpub\logs\LogFiles\ are deleted.
sigmaWindowsmedium2022-09-16Windows Security 4663: Access to Microsoft Teams token and local storage files
Identifies non-Teams.exe processes accessing Microsoft Teams cookies or local storage objects on Windows (Event 4663).
sigmaWindowshigh2022-09-16Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Detects SharPersist execution on Windows via process name and persistence-related command-line parameters.
sigmaWindowshigh2022-09-15Windows: Service Created by System Using Client with PID 0 (SCM Event 7045)
Alerts on Windows service installation events (SCM EventID 7045) where the client process ID is 0.
sigmaWindowshigh2022-09-15Windows Service Created by Client With PID 0 or Parent PID 0
Alerts on Windows service installs (EID 4697) where the client or parent PID is 0.
sigmaWindowshigh2022-09-15Windows CLI Processes Using Common Weak or Abused Passwords
Alerts when Windows command lines include common weak or reused password values.
sigmaWindowsmedium2022-09-14Windows PowerShell Disables Windows Firewall Profiles via Set-NetFirewallProfile
Flags PowerShell commands attempting to turn off Windows Firewall profiles using Set-NetFirewallProfile.
sigmaWindowsmedium2022-09-14Suspicious ntdsutil.exe Use for AD Snapshot Mount or Activation (Windows Process Creation)
Alerts on ntdsutil.exe command lines that include snapshot mount and activation/instance fragments, indicating potential AD snapshot manipulation.
sigmaWindowsmedium2022-09-14Windows UAC Bypass via Elevated COM interface using ICMLuaUtil
Flags dllhost.exe parent launches tied to elevated COM /Processid GUIDs consistent with UAC bypass behavior on Windows.
sigmaWindowshigh2022-09-13Windows: Taskkill used to terminate ccSvcHst.exe (Symantec Endpoint Protection service impairment)
Flags Windows taskkill /F /IM ccSvcHst.exe executions that can disable Symantec Endpoint Protection services.
sigmaWindowshigh2022-09-13Windows Process Creation: Chisel Tunneling Tool (chisel.exe) Execution
Flags Windows executions of chisel.exe with client/server tunneling and SOCKS5 reverse arguments.
sigmaWindowshigh2022-09-13