Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows file write events where executables save files with suspicious script/binary extensions
Alerts when common Windows system executables write files ending in suspicious extensions like .ps1, .bat, .vbs, or .hta.
sigmaWindowshigh2022-08-12Windows Malicious iphlpapi.dll Dropped in OneDrive/Teams AppData Directory
Flags creation of iphlpapi.dll in the Microsoft AppData area used by OneDrive/Teams, consistent with DLL sideloading attempts.
sigmaWindowshigh2022-08-12Windows Service Installation of AnyDesk Software (Service Control Manager 7045)
Flags Windows service creation where AnyDesk appears in the service name and ImagePath via SCM Event ID 7045.
sigmaWindowsmedium2022-08-11Windows Registry: Change to Services\WinSock2\Parameters\AutodialDLL for DLL Persistence
Alerts on registry changes to AutodialDLL under WinSock2 parameters that may enable DLL-based persistence.
sigmaWindowshigh2022-08-10Windows Registry App Paths Default Property Change Using Suspicious Values
Alerts on Windows App Paths registry edits to (Default)/Path with suspicious binaries, scripts, or temp/public locations.
sigmaWindowshigh2022-08-10Windows Startup Folder File Creation with Suspicious Script/Executable Extensions
Alerts on creation of startup-folder files with script/executable extensions commonly used for logon persistence on Windows.
sigmaWindowshigh2022-08-10Windows Registry Persistence via MyComputer \"Default\" Value Modification
Detects changes to Explorer\MyComputer (Default) registry value that can redirect a launched binary for persistence.
sigmaWindowshigh2022-08-09Windows Persistence Attempt via ErrorHandler.cmd in C:\WINDOWS\Setup\Scripts\
Alerts on writing ErrorHandler.cmd to C:\WINDOWS\Setup\Scripts\, a persistence-relevant location on Windows.
sigmaWindowsmedium2022-08-09Windows file creation for SharpHound/BloodHound collection output filenames
Flags SharpHound/BloodHound default collection export files (zip and multiple JSON datasets) from Windows file events.
sigmaWindowshigh2022-08-09Windows SafeBoot Registry Key Deletion via reg.exe Command-Line
Flags reg.exe deleting the \SYSTEM\CurrentControlSet\Control\SafeBoot registry key via command line.
sigmaWindowshigh2022-08-08Windows mshta.exe launched with URL-based arguments (http/https/ftp)
Alerts when mshta.exe is executed with HTTP/HTTPS/FTP URLs in the command line, consistent with remote HTA execution.
sigmaWindowshigh2022-08-08Windows Registry Persistence: DbgManagedDebugger Debugger Value Added
Alerts on registry sets that add a Debugger value under DbgManagedDebugger, indicating potential crash-triggered persistence.
sigmaWindowsmedium2022-08-07Windows Process Creation: Detect Use of 8.3 Short Name in Image Path (~1/~2)
Alerts on Windows process launches whose Image path contains 8.3 short-name markers (~1\ or ~2\), excluding several known benign parents.
sigmaWindowsmedium2022-08-07Windows Registry RDP Terminal Services Sensitive Settings Tampering
Flags Windows registry changes to sensitive RDP/Terminal Services settings such as shadowing, remote assistance, security, and InitialProgram.
sigmaWindowshigh2022-08-06Windows Process Creation: Image contains NTFS 8.3 short filename patterns
Flags process creation events where the Image contains Windows 8.3 short-name patterns (e.g., ~1.exe, ~2.ps1) to evade image-based detections.
sigmaWindowsmedium2022-08-06Windows Exploit Guard Controlled Folder Access: Added Allowed Application for Blocked Path
Alerts when an app is added to Exploit Guard’s AllowedApplications list to bypass controlled folder restrictions for risky paths.
sigmaWindowshigh2022-08-05Windows Registry: Exploit Guard ProtectedFolders Value Deleted
Alerts on deletion of registry values under Exploit Guard Controlled Folder Access ProtectedFolders.
sigmaWindowshigh2022-08-05Windows Process Creation: wusa.exe Cab Extraction From Suspicious Directory Paths
Flags wusa.exe with /extract: originating from common temp/public paths, a potential CAB-based payload unpacking behavior.
sigmaWindowshigh2022-08-05Windows Process Command Line Contains NTFS 8.3 Short Filename Patterns (~1/~2.*)
Detects Windows command lines referencing NTFS 8.3 short names like ~1.exe or ~2.ps1.
sigmaWindowsmedium2022-08-05Windows Process Creation: Remove-MpPreference Used to Tamper Windows Defender Settings
Flags process executions that call Remove-MpPreference with Defender tampering-related parameters.
sigmaWindowshigh2022-08-05