Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
PowerShell TCP Tunnel Indicators: HttpWebRequest and TcpListener Usage (Windows
Flags PowerShell scripts referencing TcpListener/AcceptTcpClient and HttpWebRequest as potential TCP tunneling behavior.
sigmaWindowsmedium2022-07-08Windows: Detect Named Pipe Creation with Koh Default Names
Alerts on Windows named pipe creation with Koh default identifiers in the pipe name.
sigmaWindowscritical2022-07-08Windows PowerShell: Import-Module From Temp, AppData, or Public Directories
Detects PowerShell module imports (Import-Module/ipmo) from Temp, AppData, or Public directories via Script Block Logging.
sigmaWindowsmedium2022-07-07Windows Registry Changes Disabling Windows Defender Event Log Channel
Detects registry changes that disable the Windows Defender Operational event log channel by setting its Enabled DWORD to 0.
sigmaWindowshigh2022-07-04Windows Registry Event Log Tampering by Disabling WINEVT Channel Enabled Key
Flags registry changes that set WINEVT channel Enabled to 0x00000000 to disable Windows event logging.
sigmaWindowshigh2022-07-04Windows UAC Bypass via IDiagnosticProfileUAC Triggered from DllHost.exe
Flags elevated process creation where DllHost.exe launches using the specific IDiagnosticProfileUAC /Processid value.
sigmaWindowshigh2022-07-03Windows: DllHost.exe creates a System32 DLL for UAC bypass via IDiagnosticProfileUAC
Alerts when dllhost.exe creates a System32 .dll consistent with IDiagnosticProfileUAC UAC bypass behavior.
sigmaWindowshigh2022-07-03Windows: Execution of .xbap via PresentationHost.exe from Uncommon Paths
Alerts when PresentationHost.exe launches a .xbap file from a non-standard location on Windows.
sigmaWindowsmedium2022-07-01Windows: Execution of ScriptRunner.exe with appvscript Argument
Flags ScriptRunner.exe executions that include the " -appvscript " parameter in the command line.
sigmaWindowsmedium2022-07-01Windows: Suspicious LSASS handle access via svchost.exe call trace to seclogon.dll
Flags svchost.exe attempting LSASS access (granted access 0x14c0) with seclogon.dll in the call trace.
sigmaWindowshigh2022-06-29Windows: assoc.exe Changes File Extension Handler to exefile
Alerts on cmd.exe running assoc to set file extension handlers to exefile, indicating possible persistence via file associations.
sigmaWindowshigh2022-06-28Windows Process Creation: bitsadmin Downloads Files to Suspicious Directories
Flags bitsadmin.exe file downloads that target suspicious folders using /transfer, /create, and /addfile command-line parameters.
sigmaWindowshigh2022-06-28Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension
Flags bitsadmin.exe commands that transfer or add files with suspicious extensions based on process creation command-line content.
sigmaWindowshigh2022-06-28Windows BITSAdmin Downloads from File-Sharing Domains
Alerts on BITSAdmin downloads from popular file-sharing domains when transfer/create/addfile command-line flags are present.
sigmaWindowshigh2022-06-28Windows Process Creation: bitsadmin Download Using Direct IP URL
Alerts when bitsadmin.exe is used to download via a direct IP address in the command line on Windows.
sigmaWindowshigh2022-06-28Windows attrib.exe sets hidden system file attribute (+s) on suspicious paths and script/executable extensions
Flags attrib.exe usage with +s to mark .exe/.dll and script files in public/temp/user-writable locations as system files.
sigmaWindowshigh2022-06-28PowerShell disables or removes ETW Trace via Set-EtwTraceProvider or Remove-EtwTraceProvider
Flags PowerShell commands that remove or disable ETW trace providers to impair Windows telemetry.
sigmaWindowshigh2022-06-28Windows BITS Transfer Job Download to Suspicious File Paths
Flags new Windows BITS transfer jobs that save downloaded files into predefined suspicious paths.
sigmaWindowshigh2022-06-28Windows BITS Client Downloads From File-Sharing Domains
Alerts on Windows BITS transfers (EventID 16403) that download from known file-sharing/content hosting domains.
sigmaWindowshigh2022-06-28Windows dllhost.exe Launched With No Command-Line Arguments
Alerts on dllhost.exe being executed with no command-line arguments, a rare pattern that may indicate stealthy or injected activity.
sigmaWindowshigh2022-06-27