Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows CreateStreamHash: Suspicious Downloads From File Sharing and Paste Websites
Identifies Windows stream-hash events tied to downloads from file-sharing/paste domains with Zone-tagged payload extensions.
sigmaWindowshigh2022-08-24Windows Registry: New NetworkProvider service keys indicative of credential dumping
Alerts on registry additions/changes to NetworkProvider service entries that may be used to dump clear-text credentials.
sigmaWindowsmedium2022-08-23Windows Process Creation Using the Sysnative Directory Path
Alerts on process executions referencing \Windows\Sysnative, excluding common ngen.exe and a known XAMPP bat launcher.
sigmaWindowsmedium2022-08-23Windows Process Creation: Suspicious CLI NetworkProvider Addition for Credential Dumping
Alerts on Windows CLI executions that reference services\... and NetworkProvider, a pattern consistent with credential dumping via provider changes.
sigmaWindowshigh2022-08-23Windows cmd.exe Command-Line Anomaly: Missing Spaces Around /c /k /r
Flags cmd.exe invocations with suspicious missing spaces around /c, /k, or /r based on process creation CommandLine patterns.
sigmaWindowshigh2022-08-23Windows Registry Persistence Risk: TypedPaths Key Modified by Non-Explorer Processes
Alerts on changes to Explorer TypedPaths registry entries from processes other than explorer.exe.
sigmaWindowshigh2022-08-22Windows Rundll32 Masquerading: DllRegisterServer CommandLine Not Using rundll32.exe
Alerts when 'DllRegisterServer' appears in the command line while the executing image is not rundll32.exe.
sigmaWindowshigh2022-08-22Windows Command-Line Persistence via TypedPaths Registry Modification
Flags command-line activity referencing the Explorer TypedPaths registry path, which may indicate persistence via registry modification.
sigmaWindowsmedium2022-08-22Windows PUA CsExec Execution via Process Creation
Flags Windows process creation of csexec.exe (CsExec) consistent with remote execution tooling usage.
sigmaWindowshigh2022-08-22Windows Process Creation: Uncommon Parent Process Launching link.exe
Alerts when link.exe is spawned with a parent process outside typical Visual Studio paths.
sigmaWindowsmedium2022-08-22Windows Process Creation: Renamed AdFind.exe Executions
Detects renamed AdFind.exe executions using AdFind-style domain discovery command-line indicators, OriginalFileName, and known binary hashes.
sigmaWindowshigh2022-08-21Windows PowerShell Command History Disable via Remove-Module psreadline
Detects PowerShell scripts that remove psreadline with Remove-Module to suppress command history evidence.
sigmaWindowshigh2022-08-21Windows Script Dropped by Signed Applications and LOLBINs
Detects Windows legitimate/signed executables dropping script files (.ps1, .vbs, .js, etc.) to disk, indicating potential script-based abuse.
sigmaWindowshigh2022-08-21Windows Suspicious App and LOLBIN Dropping Executable Files to Disk
Alerts on Windows processes like Office/LOLBINs writing .exe/.dll and other executable-equivalent files to disk.
sigmaWindowshigh2022-08-21Windows Executable Dropping Archive Files via Common LOLBINs and Office Apps
Alerts when Office or other specified Windows binaries create archive files like .zip/.rar/.7z/.diagcab/.appx on disk.
sigmaWindowshigh2022-08-21Windows Registry COM Hijacking via scrobj.dll InprocServer32(Default) Persistence
Alerts on registry modifications setting InprocServer32(Default) to scrobj.dll, indicating possible COM hijacking persistence.
sigmaWindowsmedium2022-08-20Windows Process Creation: WebBrowserPassView.exe Execution
Flags Windows execution of WebBrowserPassView.exe, a browser password recovery tool often used for credential access.
sigmaWindowsmedium2022-08-20Windows: Code execution via Pester.bat invoked by PowerShell (Invoke-Pester/Get-Help)
Alerts when PowerShell spawns Pester.bat with parent command lines referencing Pester invocation or help usage.
sigmaWindowsmedium2022-08-20Windows Process Creation: TruffleSnout.exe Execution
Detects execution of TruffleSnout.exe on Windows using process creation metadata.
sigmaWindowshigh2022-08-20Windows: SharpUp (SharpUp.exe) Local Privilege Escalation Tool Execution
Flags SharpUp.exe execution on Windows when command line indicators reference common privilege-escalation targets.
sigmaWindowscritical2022-08-20