Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell ScriptBlock: Remove-MpPreference Tampering of Defender Configuration
Detects PowerShell commands removing Defender preferences via Remove-MpPreference with additional Defender setting indicators.
sigmaWindowshigh2022-08-05Windows Suspicious File Creation in AppData Outside Common Subdirectories
Alerts on new .exe/.dll/.ps1/.lnk and other files created under unusual AppData locations outside Local/LocalLow/Roaming.
sigmaWindowshigh2022-08-05Windows Defender Exploit Guard Tamper via Controlled Folder Access AllowedApplications or ProtectedFolders Changes
Alerts on Windefend EventID 5007 when Exploit Guard ProtectedFolders or AllowedApplications lists are modified.
sigmaWindowshigh2022-08-05Windows RDP Tunneling Using plink.exe on Local Port 3389
Alert on plink.exe command lines referencing 127.0.0.1:3389 or port 3389, suggesting potential RDP tunneling on Windows.
sigmaWindowshigh2022-08-04Windows Suspicious IIS Module Registration via w3wp.exe, appcmd.exe, and PowerShell/gacutil
Flags w3wp.exe-launched appcmd.exe module registrations involving PowerShell publication or gacutil GAC installation.
sigmaWindowshigh2022-08-04Windows PsExec Named Pipe Creation from Suspicious Paths (PSEXESVC)
Alerts on PsExec pipe \PSEXESVC creation when the executing image path is in public/temp/desktop/downloads locations.
sigmaWindowsmedium2022-08-04Windows CLI usage of obfuscated IP address patterns in ping/arp commands
Alerts when ping or arp command lines include obfuscated/encoded IP address indicators on Windows.
sigmaWindowsmedium2022-08-03Windows Process Creation: Obfuscated IP Address in Download Command URLs
Alerts on Windows download commands that include obfuscated/encoded IP addresses in the URL.
sigmaWindowsmedium2022-08-03Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
sigmaWindowscritical2022-08-03Windows Security Mitigations: Unsigned DLL Blocked from User-Writable Paths
Alerts on blocked unsigned DLL loads targeting public, downloads, desktop, or temp directories in Windows Security Mitigations logs.
sigmaWindowshigh2022-08-03Windows Security: DiagTrackEoP POC Default UserName Login Attempt (LogonType 9)
Alerts on Windows 4624 LogonType 9 events targeting a known DiagTrackEoP default username.
sigmaWindowscritical2022-08-03Windows Command-Line Tools Performing Web POST Exfiltration via IWR/curl/wget
Identifies PowerShell/curl/wget commands on Windows that use POST-style web requests combined with data-dumping or discovery payloads.
sigmaWindowshigh2022-08-02Windows PowerShell Invoke-WebRequest Download to Suspicious Paths
Alert when PowerShell uses Invoke-WebRequest/aliases with download flags and targets suspicious file locations.
sigmaWindowshigh2022-08-02Windows: Detect VMwareXferlogs.exe Executed from Non-default Path
Alert on VMwareXferlogs.exe launching from an unexpected directory, a potential DLL sideloading technique on Windows.
sigmaWindowshigh2022-08-02Windows mpclient.dll Sideloading via MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when mpclient.dll is loaded by MpCmdRun.exe or NisSrv.exe outside known Windows Defender directories.
sigmaWindowshigh2022-08-02Windows: Potential DLL sideloading via VMwareXferlogs loading glib-2.0.dll from non-standard path
Alerts on VMwareXferlogs.exe loading glib-2.0.dll from outside the default VMware directory.
sigmaWindowshigh2022-08-02Windows Code Integrity blocks unsigned DLL loads into MpCmdRun.exe and NisSrv.exe
Flags security-mitigations events where MpCmdRun or NisSrv are prevented from loading unsigned DLLs.
sigmaWindowshigh2022-08-02Windows Registry Set to Disable Windows Defender Components
Flags registry changes that turn off Windows Defender protections via Defender and Security Center policy keys.
sigmaWindowshigh2022-08-01Windows Registry: Attachment Manager policy tampering via Attachments settings values
Detects registry changes to Windows Attachment Manager policy values that can disable or alter download safety controls.
sigmaWindowshigh2022-08-01Windows Registry Tampering: Attachment Manager Associations Default File Type Risk and LowRiskFileTypes
Flags Windows registry changes to Attachment Manager associations that set DefaultFileTypeRisk and modify LowRiskFileTypes.
sigmaWindowshigh2022-08-01