Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows UAC Bypass via iscsicpl.exe DLL Search Order Hijacking (iscsiexe.dll)
Detects iscsicpl.exe loading iscsiexe.dll from outside C:\Windows, consistent with UAC bypass DLL hijacking.
sigmaWindowshigh2022-07-17Windows System Process Loads DLL from Suspicious or Permissive Paths
Alerts when a Windows system process loads a DLL from permissive or suspicious directories.
sigmaWindowsmedium2022-07-17Windows Process Creation: NTVDM (ntvdm.exe/csrstub.exe) Start for 16-bit App Compatibility
Flags creation of NTVDM-related processes (ntvdm.exe or csrstub.exe) used to run legacy 16-bit/DOS applications on Windows.
sigmaWindowsmedium2022-07-16Windows Process Initiated Connections to Ngrok Domains
Alerts when a Windows process initiates an outbound connection to ngrok domain hostnames, which may indicate staging or C2 activity.
sigmaWindowshigh2022-07-16Windows Scheduled Task Creation Triggered Once at 00:00 Using Scripted Commands
Alerts on suspicious schtasks.exe task creation for a one-time 00:00 run with embedded script/command execution strings.
sigmaWindowshigh2022-07-15Sysmon DNS Query for anonfiles.com Domain
Flags Windows Sysmon DNS queries referencing anonfiles.com to support detection of suspicious data staging.
sigmaWindowshigh2022-07-15Windows Suspicious Service Creation via sc.exe or PowerShell New-Service with Abnormal Binary Paths
Flags service creation commands (sc.exe/New-Service) when the specified binary path includes suspicious directories or script/loader utilities.
sigmaWindowshigh2022-07-14Windows: Detect sc.exe Creating Kernel Driver Services
Flags sc.exe service creation where the command-line specifies a kernel driver type and binPath.
sigmaWindowsmedium2022-07-14MSSQL sp_procoption Startup Execution Set/Clear via Application Log EventID 33205
Alerts on MSSQL sp_procoption being set or cleared for automatic startup execution via EXEC (EventID 33205).
sigmaWindowshigh2022-07-13Windows/MSSQL: Detect ALTER SERVER AUDIT or DROP SERVER AUDIT executions
Alerts on MSSQL ALTER/DROP SERVER AUDIT statements that disable or delete server audit coverage.
sigmaWindowshigh2022-07-13Windows MSSQL: Add Member to sysadmin Server Role (EventID 33205)
Alerts on MSSQL EventID 33205 when an ALTER SERVER ROLE command adds a member to the sysadmin role.
sigmaWindowshigh2022-07-13Windows Registry: Hidden User via Winlogon SpecialAccounts Userlist Value 0
Alerts on Windows registry updates that set Winlogon SpecialAccounts Userlist to DWORD 0 to hide users.
sigmaWindowshigh2022-07-12Windows: Base64-Encoded PE “MZ” Header Present in Command Line
Alerts when Windows command lines include Base64 strings matching a PE “MZ” header.
sigmaWindowshigh2022-07-12Windows: Local user creation via net.exe with expires:never
Flags net.exe user add commands that set expires:never for local account persistence.
sigmaWindowshigh2022-07-12Windows: Detect Suspicious mofcomp.exe Execution from Scripts or Temp Paths
Flags mofcomp.exe runs spawned by script interpreters or using temp/AppData paths, with exclusions for WmiPrvSE .mof-related activity.
sigmaWindowshigh2022-07-12Windows cmd.exe Output Redirection to User Writable Paths
Flags cmd.exe commands that redirect output (>) into temp/AppData and other commonly targeted directories.
sigmaWindowsmedium2022-07-12Windows MSSQL xp_cmdshell Setting Change (EventID 15457)
Flags MSSQL xp_cmdshell setting changes using Windows application EventID 15457 events containing 'xp_cmdshell'.
sigmaWindowshigh2022-07-12Windows MSSQL xp_cmdshell Command Execution via Application Event 33205
Alerts when SQL Server xp_cmdshell is invoked to execute commands, using Windows application EventID 33205 data.
sigmaWindowshigh2022-07-12Windows PowerShell: Detect Command Lines with Suspicious UTF-16 Base64 Obfuscation Patterns
Alerts on PowerShell command lines containing suspicious UTF-16/Base64 obfuscation fragments indicative of hidden script logic.
sigmaWindowshigh2022-07-11Windows DNS Queries to Remote Support and Remote Access Domains From Non-Browser Processes
Alert on DNS lookups for remote access service domains from non-browser executables, including RustDesk subdomains.
sigmaWindowsmedium2022-07-11