Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: 3proxy Proxy Server Execution
Detects execution of 3proxy.exe with local 127.0.0.1 proxy binding on Windows.
sigmaWindowshigh2022-09-13PowerShell Script Block Logging: Suspicious Windows Event Log Clearing Cmdlets
Flags PowerShell script blocks that call event log clearing cmdlets or ClearLog to impair Windows log visibility.
sigmaWindowsmedium2022-09-12PowerShell Enable-WindowsOptionalFeature Enables Suspicious Windows Optional Features (Windows)
Alerts on PowerShell enabling Windows optional features online for specific, potentially risky feature names.
sigmaWindowsmedium2022-09-10PowerShell Disable-WindowsOptionalFeature -Online -FeatureName for Windows Defender features
Detects PowerShell disabling online Windows Defender features via Disable-WindowsOptionalFeature -FeatureName.
sigmaWindowshigh2022-09-10Windows Registry Winlogon AllowMultipleTSSessions Enabled
Alerts on enabling Winlogon AllowMultipleTSSessions (DWORD 0x00000001), allowing concurrent RDP sessions.
sigmaWindowsmedium2022-09-09Windows Process Creation Recon via Event Log Query Tools and Event ID Searches
Flags Windows processes running event log query utilities and commands that search specific event IDs or dump log content.
sigmaWindowsmedium2022-09-09Windows Schtasks.exe Scheduled Task Creation or Modification with Suspicious Schedule Types
Alerts on schtasks.exe commands that schedule tasks using ONLOGON/ONSTART/ONCE/ONIDLE with potentially malicious privilege context.
sigmaWindowshigh2022-09-09Windows schtasks Delete All Scheduled Tasks via /tn * /delete /f
Flags schtasks.exe commands that forcibly delete all scheduled tasks on the local host using /delete /tn * /f.
sigmaWindowshigh2022-09-09Windows schtasks.exe Used to Delete Scheduled Tasks for System and Security Components
Alerts when schtasks.exe runs with /delete targeting sensitive Windows scheduled tasks that support security, updates, or recovery.
sigmaWindowshigh2022-09-09Windows vmnat.exe Renamed Execution for Possible DLL Side-Loading
Alerts on Windows processes where vmnat.exe appears renamed, which may support stealthy execution and DLL side-loading behavior.
sigmaWindowshigh2022-09-09PowerShell User Discovery and Export with Get-ADUser
Flags PowerShell Get-ADUser enumeration (filter *) followed by exporting results to a file.
sigmaWindowsmedium2022-09-09Windows Root Certificate Installation from Suspicious Paths via PowerShell Import-Certificate
Alerts on PowerShell importing a root certificate into Cert:\LocalMachine\Root from suspicious file paths on Windows.
sigmaWindowshigh2022-09-09PowerShell Email Address Exfiltration via EXIF-style Recipient Harvesting on Windows
Alerts when PowerShell command lines enumerate Exchange recipients and expand email address properties, indicating potential email data exfiltration.
sigmaWindowshigh2022-09-09Windows node.exe Execution with -e/--eval and suspicious child process usage
Alerts on node.exe started with -e/--eval and command-line indicators of child_process and net.socket connect activity.
sigmaWindowshigh2022-09-09Windows Security: Suspicious SAMTHEADMIN-* Computer/Account Names Ending with $
Alerts on Windows Security events with computer account names starting SAMTHEADMIN- and ending with $.
sigmaWindowscritical2022-09-09Windows WMIC System Reconnaissance Using "computersystem" Flag
Flags wmic.exe runs that include the "computersystem" argument for Windows host information discovery.
sigmaWindowsmedium2022-09-08Windows Process Creation: SharpEvtMute Execution (Event Log Tampering)
Alerts on SharpEvtMute.exe runs with event-log filter and encoded command-line parameters on Windows.
sigmaWindowshigh2022-09-07Windows SysmonEnte Process Access Attempt (Sysmon.exe/ Sysmon64.exe/ Sysmon64a.exe)
Flags attempts to access Sysmon binaries consistent with SysmonEnte execution based on TargetImage, GrantedAccess, and CallTrace.
sigmaWindowshigh2022-09-07Windows: Detect EvtMuteHook.dll Load by IMPHASH Match (SharpEvtMute)
Detects DLL loads with a specific IMPHASH consistent with EvtMuteHook.dll used for event log tampering.
sigmaWindowshigh2022-09-07Windows suspicious file download URLs using direct IP address with script/binary extensions
Alerts on Windows downloads from HTTP/HTTPS direct IP URLs targeting script/binary/shortcut-like filenames.
sigmaWindowshigh2022-09-07