Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows RTCore64 Service Installation via Service Control Manager (Event ID 7045)
Alerts on creation of the RTCore64 Windows service via Service Control Manager Event ID 7045.
sigmaWindowshigh2022-08-30Windows SharpLdapWhoami Execution via LDAP Whoami Methods
Flags execution of SharpLdapWhoami on Windows using LDAP-related whoami alternative method parameters.
sigmaWindowshigh2022-08-29Potential DLL Sideloading via DeviceEnroller.exe Using /PhoneDeepLink
Alerts on deviceenroller.exe runs with /PhoneDeepLink, a potential DLL sideloading trigger referencing ShellChromeAPI.dll.
sigmaWindowsmedium2022-08-29Windows Registry Detection: COM TreatAs(Default) Hijacking
Flags registry changes to COM TreatAs(Default) keys, excluding common Office/ClickToRun and installer processes.
sigmaWindowsmedium2022-08-28Windows Process Creation: nimgrab.exe Execution (Nim Tool Download Behavior)
Alerts on execution of nimgrab.exe on Windows when hashes match known indicators.
sigmaWindowshigh2022-08-28Windows Network Connections by wscript/cscript Script Interpreters to Non-Local IPs
Flags wscript.exe/cscript.exe making outbound connections to non-local destination IPs.
sigmaWindowshigh2022-08-28Windows Wscript/Cscript Initiating Local Network Connection for Script Retrieval
Flags wscript.exe or cscript.exe making connections to local/private destination IP ranges on Windows.
sigmaWindowsmedium2022-08-28Windows Scheduled Task Index Registry Tampering Hiding Tasks from Query Tools
Alerts on registry set events that tamper scheduled task TaskCache Tree "Index" DWORD to 0.
sigmaWindowshigh2022-08-26Windows Registry: Scheduled Task Index Value Removal to Hide Task (TaskCache)
Alerts on deletion of the Scheduled Tasks TaskCache Tree 'Index' value used by tools to enumerate tasks.
sigmaWindowsmedium2022-08-26Suspicious SysAidServer Child Processes via Java on Windows
Flags SysAidServer process spawning java.exe/javaw.exe on Windows to surface likely suspicious execution.
sigmaWindowsmedium2022-08-26Windows Process Execution of Regasm/Regsvcs from Uncommon Directories
Alerts on Regasm/Regsvcs executions from commonly abused non-standard directories using process creation image and command line fields.
sigmaWindowsmedium2022-08-25Windows process command line matching Sliver C2 implant NoExit PowerShell UTF8 pattern
Alerts on Windows process command lines matching a Sliver-style PowerShell -NoExit encoding pattern.
sigmaWindowscritical2022-08-25Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Alerts on Service Control Manager EventID 7045 for Sliver service installations using a known Temp-staged EXE path pattern.
sigmaWindowshigh2022-08-25Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Flags Windows registry writes to \EulaAccepted for Sysinternals-related objects when performed by non-matching executables.
sigmaWindowshigh2022-08-24Windows Registry Set: Sysinternals EULA Accepted Key for PUA Tool Execution
Flags Sysinternals-related registry EULA acceptance writes tied to PsExec/ProcDump/Process Explorer and other tools.
sigmaWindowsmedium2022-08-24Windows Registry: Sysinternals Renamed Tool Execution Indicator via EulaAccepted Key
Flags registry writes to EulaAccepted for Sysinternals-named targets when executed by non-matching image filenames.
sigmaWindowshigh2022-08-24Windows File Changes to Microsoft.VSCode_profile.ps1 via PowerShell Profile
Detects creation or modification of Microsoft.VSCode_profile.ps1 based on Windows file events.
sigmaWindowsmedium2022-08-24Windows msdt.exe Creating Files in Common Startup and Public Directories
Alerts when msdt.exe writes files to high-suspicion directories that may indicate persistence after exploitation.
sigmaWindowshigh2022-08-24Windows Named Pipe Stream Created with Known Hack Tool IMPHASHs
Alerts on Windows named file stream creation events whose IMPHASH matches common hack-tool binaries.
sigmaWindowshigh2022-08-24Windows Suspicious File Download Streams From File/Paste Hosting Domains With Script Extensions
Alert on Windows file stream hash creation involving downloads from paste/file-sharing domains targeting .bat/.cmd/.ps1 content indicators.
sigmaWindowsmedium2022-08-24