Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: DirLister.exe Execution for Directory Listing Discovery
Alerts on execution of DirLister.exe on Windows, indicating potential directory/file discovery activity.
sigmaWindowslow2022-08-20Windows DNS Query for _ldap.* Using LDAP-Related Discovery
Alerts on _ldap.* DNS queries from uncommon Windows processes, indicating potential LDAP/DNS service discovery.
sigmaWindowslow2022-08-20Windows Registry Modification: Suppress Windows Security Center Notifications
Flags setting Notification_Suppress DWORD to 1 in Windows Defender UX policy to disable security center notifications.
sigmaWindowsmedium2022-08-19Windows Registry: Set DisallowRun DWORD to 0x1 to Block User Program Execution
Detects Windows registry writes setting Explorer\DisallowRun to DWORD 0x1, a defense-impairment behavior.
sigmaWindowsmedium2022-08-19Windows Registry: Disable Firewall via EnableFirewall DWORD Policies
Flags registry policy changes that set Windows Firewall EnableFirewall to 0 for Domain or Standard profiles.
sigmaWindowsmedium2022-08-19Windows Registry: Disable Windows Security Center notifications via UseActionCenterExperience
Alerts on registry updates that set UseActionCenterExperience=0 to disable Windows Security Center notifications.
sigmaWindowsmedium2022-08-19Windows Registry: Enable RDP Remote Assistance via fAllowToGetHelp
Alerts when Windows enables remote assistance via Terminal Server fAllowToGetHelp (0x1) registry change.
sigmaWindowsmedium2022-08-19Windows: Uncommon Child Processes Spawned by sigverif.exe
Alerts when sigverif.exe spawns unusual child processes on Windows, excluding common WerFault.exe cases.
sigmaWindowsmedium2022-08-19Windows reg.exe Adds or Modifies Suspicious Registry Locations via Command Line
Alerts on reg.exe registry modifications targeting specific Windows policy, security, Defender, and credential-related paths.
sigmaWindowshigh2022-08-19Windows Process Creation: reg.exe Modifying Group Policy Registry Settings
Flags reg.exe commands targeting Group Policy System registry settings related to security and policy refresh.
sigmaWindowsmedium2022-08-19Windows PresentationHost.EXE downloading files via URL in command line
Flags PresentationHost.EXE executions whose command line includes http/https/ftp URLs, indicating potential arbitrary file downloads.
sigmaWindowsmedium2022-08-19Windows: MSPUB.EXE Downloading Arbitrary Files via HTTP/FTP URIs
Flags MSPUB.EXE executions with HTTP/FTP URLs that may indicate arbitrary file downloads.
sigmaWindowsmedium2022-08-19Windows: MSOHTMED.EXE Arbitrary File Download Using HTTP/FTP URLs
Alerts when MSOHTMED.EXE is executed with HTTP/FTP URLs to download an arbitrary file.
sigmaWindowsmedium2022-08-19Windows Register_app.vbs Proxy COM+ Provider Registration via Process Command-Line
Alerts when REGISTER_APP.VBS is executed with -register to register a VSS/VDS provider as a COM+ application.
sigmaWindowsmedium2022-08-19Windows: Launch-VsDevShell.ps1 Proxy Execution via Process Command Line
Detects command-line usage of Launch-VsDevShell.ps1 with Visual Studio path flags on Windows.
sigmaWindowsmedium2022-08-19Windows InstallUtil.exe Downloading Files via HTTP/FTP
Flags InstallUtil.exe execution with http/https/ftp URLs indicative of remote file downloads on Windows.
sigmaWindowsmedium2022-08-19Windows DeviceCredentialDeployment.exe Execution for Process Stealth (T1218)
Flags Windows process execution when DeviceCredentialDeployment.exe starts.
sigmaWindowsmedium2022-08-19Windows: Suspicious CustomShellHost.exe execution spawned by non-Explorer parent
Alerts on CustomShellHost.exe executions where explorer.exe is not the expected parent process image.
sigmaWindowshigh2022-08-19Windows PowerShell: GPO ScriptBlock Modifying Group Policy and SmartScreen Settings
Alerts on PowerShell ScriptBlock content referencing Group Policy policy keys and specific security policy value names.
sigmaWindowsmedium2022-08-19Windows Process Execution of HandleKatz LSASS Dumper (loader.exe)
Flags HandleKatz-style loader.exe executions that dump LSASS into obfuscated .obf files using --pid and --outfile.
sigmaWindowshigh2022-08-18