Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry Change Disabling WinDefend Service (WinDefend Start=4)
Flags registry changes that set WinDefend service Start to 0x4, indicating potential defensive impairment.
sigmaWindowshigh2022-08-01Windows Registry AutoLogger Session Disable/Start Tampering via Event Log Targets
Alerts when registry changes disable or stop AutoLogger sessions for EventLog-* or Defender by setting Enabled/Start to 0x0.
sigmaWindowshigh2022-08-01Windows sc.exe Service StartupType Change to Disabled or Demand
Flags sc.exe commands that change a Windows service startup type to disabled or demand.
sigmaWindowsmedium2022-08-01Windows reg.exe importing .reg files from common user and temp directories
Flags reg.exe importing .reg files when the command line references user or temp directories.
sigmaWindowsmedium2022-08-01Windows reg.exe deletes service registry keys using the delete flag
Alerts on reg.exe command lines that delete entries under the Windows services registry path.
sigmaWindowshigh2022-08-01Windows query.exe used to enumerate sessions and processes (possible data exfil staging)
Detects query.exe runs that request session and process output, matching patterns consistent with staged data collection.
sigmaWindowsmedium2022-08-01Windows Defender mpclient.dll Side-loading: MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when MpCmdRun.exe or NisSrv.exe runs from non-default directories, a common indicator of possible mpclient.dll sideloading.
sigmaWindowshigh2022-08-01Windows dnscmd.exe DNS Zone and Record Enumeration Command Execution
Flags dnscmd.exe executions that enumerate DNS zones/records via process creation command-line parameters.
sigmaWindowsmedium2022-07-31Windows ISO File Creation in User Temp and Outlook Cache Folders
Alerts on creation of .iso files in Windows AppData temp or Outlook cache paths.
sigmaWindowshigh2022-07-30Windows DLL Search Order Hijack via Space in System Directory Paths
Alerts on .dll events targeting Windows system paths with an extra space, indicative of DLL search order hijacking.
sigmaWindowshigh2022-07-30Windows Sysmon Driver Altitude Registry Changes
Identifies registry writes that change the Sysmon instance altitude value, which can disrupt Sysmon loading at boot.
sigmaWindowshigh2022-07-28Windows schtasks Scheduled Task Create/Modify Running as SYSTEM
Alerts on Windows schtasks task create/modify commands that set the run account to NT AUTHORITY\SYSTEM.
sigmaWindowshigh2022-07-28Windows: Suspicious Scheduled Task Modification via schtasks /Change /TN
Flags schtasks.exe executions that modify existing scheduled tasks (/Change /TN) using suspicious locations and command-line payload tooling.
sigmaWindowshigh2022-07-28Windows File Creation: Suspicious DLL/EXE/SYS in Spool Drivers Color Folder
Alerts on creation of .dll, .exe, or .sys files under C:\Windows\System32\spool\drivers\color.
sigmaWindowsmedium2022-07-28Windows Registry: Appx DebugPath Key for Potential Persistence
Detects registry set activity involving AppX DebugPath entries that may indicate persistence via packaged app debug configuration.
sigmaWindowsmedium2022-07-27Windows Browser Launched with Remote Debugging Flags
Alerts on Windows launches of Chromium-based browsers or Firefox with remote debugging command-line flags.
sigmaWindowsmedium2022-07-27Windows: WinRing0 Driver Load via Image Hash and File Name Match
Alerts on Windows driver loads matching WinRing0 modules by IMPhash or expected WinRing0 filenames.
sigmaWindowshigh2022-07-26Windows: Detect SelectMyParent PPID Spoofing Tool Execution
Flags SelectMyParent.exe process creation with PPID spoofing command-line and metadata indicators on Windows.
sigmaWindowshigh2022-07-23Suspicious PDQDeployRunner Execution on Windows with Encoded/Download Indicators
Alerts on child process activity from PDQDeployRunner parents showing encoded, hidden, or download-related command line indicators.
sigmaWindowsmedium2022-07-22Windows Service Installation: PDQDeployRunner Remote Service Creation (Service Control Manager)
Flags new Windows services installed with PDQDeployRunner-* naming via Service Control Manager event 7045.
sigmaWindowsmedium2022-07-22