Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows driver load of HackSys Extreme Vulnerable Driver (HEVD.sys) via image hash
Flags Windows systems when HEVD driver \HEVD.sys is loaded with known IMPHASH values.
sigmaWindowshigh2022-08-18Windows Malicious Driver Load by Known Hashes
Alerts on Windows driver loads matching known malicious driver hashes (MD5/SHA1/SHA256/IMPHASH).
sigmaWindowshigh2022-08-18Windows Executable Connections to Dead Drop Resolver Domains Excluding Common Browsers
Flags non-browser Windows executables making outbound connections to known dead-drop resolver domain patterns.
sigmaWindowshigh2022-08-17Windows DLL sideloading via third-party application directories (ImageLoad event)
Flags Windows ImageLoad events for specific DLL sideloading candidates tied to Lenovo and Toshiba software.
sigmaWindowsmedium2022-08-17Windows: Detect Microsoft Office DLL sideloading via ImageLoad of outllib.dll from nonstandard path
Alerts on outllib.dll loads from non-standard locations rather than typical Microsoft Office directories.
sigmaWindowshigh2022-08-17Windows Chrome Frame Helper DLL Sideloading via Image Load
Alerts when chrome_frame_helper.dll loads from an unexpected location on Windows, indicating possible DLL sideloading.
sigmaWindowsmedium2022-08-17Windows DLL Sideloading Using Antivirus/Vendor DLLs Based on Loaded Image Names
Alerts on suspicious DLL loads matching known antivirus/security component DLL names when not from expected vendor paths.
sigmaWindowsmedium2022-08-17Sysmon FileBlockExecutable event: blocked executable execution attempts on Windows
Alerts when Sysmon blocks an attempted executable execution due to FileBlockExecutable policy violations.
sigmaWindowshigh2022-08-16PowerShell Write-EventLog with -RawData Flag
Alerts when PowerShell script blocks call Write-EventLog using the -RawData flag.
sigmaWindowsmedium2022-08-16Windows Process Creation: mshtml.dll RunHTMLApplication Execution via Protocol Handlers
Alerts on Windows command lines invoking mshtml.dll RunHTMLApplication (via #135) with path traversal markers.
sigmaWindowshigh2022-08-14Windows Firewall rule deleted via netsh.exe command line
Flags netsh.exe executions that contain Windows Firewall rule deletion commands.
sigmaWindowsmedium2022-08-14Windows DLL Sideloading: System DLL Names Loaded from Non-Standard Paths (ImageLoad)
Alerts when Windows image loads DLL names typically found in system locations, excluding common benign paths to reduce false positives.
sigmaWindowshigh2022-08-14Windows rundll32 Loading Renamed comsvcs.dll via DLL Image Load
Flags rundll32.exe loading a renamed comsvcs.dll module consistent with process memory dumping behavior on Windows.
sigmaWindowshigh2022-08-14Windows Shell-Core: Installed Application Shortcut Indicators for Known Tools
Flags suspicious installation-style activity in Windows shell-core based on EventID 28115 app resolver cache entries for specific tools.
sigmaWindowsmedium2022-08-14Windows: Detect ESENT New Database Created with ntds.dit Written to Suspicious Path
Identifies ESENT EventID 325 where a new database containing ntds.dit is created in suspicious locations.
sigmaWindowsmedium2022-08-14Windows ntdsutil Abuse Indicators via ESENT Events Containing ntds.dit
Flags ESENT application events mentioning ntds.dit that may indicate ntdsutil attempts to access the AD database.
sigmaWindowsmedium2022-08-14Windows: Unusual Process Tree for wab.exe and wabmig.exe
Alert on abnormal parent/child process relationships involving wab.exe and wabmig.exe in Windows process creation logs.
sigmaWindowshigh2022-08-12Windows Process Creation: wab.exe or wabmig.exe Run from Non-Default Paths
Alerts when wab.exe or wabmig.exe run from unexpected directories on Windows.
sigmaWindowshigh2022-08-12Windows: User Added to Local Administrators Group via Net or Add-LocalGroupMember
Flags Windows command lines that add a user to the local administrators group via net.exe or Add-LocalGroupMember.
sigmaWindowsmedium2022-08-12Windows: findstr.exe LSASS keyword matching for process reconnaissance
Alert on find.exe/findstr.exe command lines containing "lsass", indicating potential LSASS-focused reconnaissance.
sigmaWindowshigh2022-08-12