Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: WinAPI Function Names in Command-Line
Alerts on Windows processes whose command lines reference WinAPI functions/modules commonly used for dynamic invocation and memory/process manipulation.
sigmaWindowshigh2022-09-06Windows Process Creation: Renamed Sysinternals Sdelete Execution
Alerts on Windows processes created with OriginalFileName sdelete.exe but executed via renamed sdelete binary paths.
sigmaWindowshigh2022-09-06Windows PowerShell DNS TXT Download Cradle via nslookup (Process Creation)
Flags PowerShell spawning nslookup configured to query DNS TXT records as a download cradle.
sigmaWindowsmedium2022-09-05Windows SharpChisel Command-Line Execution via SharpChisel.exe
Alerts on Windows process executions where the SharpChisel executable or Product metadata indicates SharpChisel.
sigmaWindowshigh2022-09-05Windows: Detect QuarksPwDump.exe Credential Dumping via Command-Line Parameters
Flags QuarksPwDump.exe executions on Windows that attempt local/domain hash and related data dumping.
sigmaWindowshigh2022-09-05Windows File Events: Suspicious Executable File Name Creation
Alerts on Windows file creation with suspicious executable filename patterns, including .bat.exe/.sys.exe and deceptive path-based names.
sigmaWindowshigh2022-09-05Windows Registry Tampering Targeting Sophos AV Tamper Protection Enabled Flags
Flags Windows registry changes that disable Sophos AV tamper protection by clearing specific enabled DWORD values.
sigmaWindowshigh2022-09-02Windows Process Creation: reg.exe Adds or Copies SafeBoot Registry Keys
Flags reg.exe with add/copy used against SafeBoot registry keys in Windows process creation logs.
sigmaWindowshigh2022-09-02Windows Process Execution of Fast Reverse Proxy (FRP) frpc.exe or frps.exe
Alerts on Windows execution of FRP components (frpc.exe/frps.exe) with FRP indicators via command line or known hashes.
sigmaWindowshigh2022-09-02Windows: Detect Ldifde.exe LDAP import (-i -f) usage
Flags Ldifde.exe being run with LDAP import parameters (-i and -f) that may trigger remote content retrieval.
sigmaWindowsmedium2022-09-02Windows certutil.exe Initiates Network Connections to Common Service Ports
Alerts when certutil.exe initiates outbound network connections to ports 80, 135, 443, or 445 on Windows.
sigmaWindowshigh2022-09-02Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.
sigmaWindowshigh2022-09-01Windows Process Creation: Suspicious ShellExec_RunDLL Command-Line Usage
Detects Windows command lines containing ShellExec_RunDLL along with other suspicious execution indicators.
sigmaWindowshigh2022-09-01Windows net.exe Commands Manipulating Built-in Default Accounts (administrator/guest)
Flags net.exe/net1.exe process creation when command lines reference built-in Administrator/guest/default accounts with suspicious active/disable context.
sigmaWindowshigh2022-09-01Windows Suspicious cmd.exe Launch After net use Mounting WebDAV Share
Flags cmd.exe command lines that mount an Internet WebDAV share with net use and immediately execute content from DavWWWRoot.
sigmaWindowshigh2022-09-01Windows schtasks.exe scheduled task creation or modification with high privileges on suspicious schedule types
Flags schtasks.exe commands that create/modify tasks to run on ONLOGON/ONSTART/ONCE/ONIDLE with SYSTEM or HIGHEST privileges.
sigmaWindowsmedium2022-08-31Windows Process Creation: Wscript.Shell.Run keyword sequence in CommandLine
Alerts on Windows command lines containing Wscript.Shell.Run keyword sequence, suggesting script-driven shell execution.
sigmaWindowsmedium2022-08-31Windows Process Creation: DefenderCheck.exe Execution (PUA/Signature Evasion)
Alerts on execution of DefenderCheck.exe/description to identify potential AV signature probing and evasion preparation.
sigmaWindowshigh2022-08-30Windows Network Connection from Cmstp.EXE (Outbound)
Alerts on outbound network connections initiated by cmstp.exe, which is uncommon and may indicate process misuse.
sigmaWindowshigh2022-08-30Windows: cmstp.exe Loading DLL/OCX from Suspicious Paths
Alerts when cmstp.exe loads DLL/OCX from suspicious directories on Windows.
sigmaWindowshigh2022-08-30