Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows HandleKatz: Duplicate LSASS Handle via Process Access with Handle Duplication Rights
Flags HandleKatz-style behavior duplicating an existing LSASS handle using PROCESS_DUP_HANDLE and ntdll.dll call trace.
sigmaWindowshigh2022-06-27Windows WerFault LSASS Memory Dump File Creation
Flags WerFault dump creation where the dump filename suggests it contains LSASS memory.
sigmaWindowshigh2022-06-27Windows: Potential Process Injection via Msra.exe Spawning Suspicious Child Processes
Flags Msra.exe spawning suspicious tools that may indicate process injection or post-exploitation activity on Windows.
sigmaWindowshigh2022-06-24Windows DNS Queries Containing ufile.io Domain
Alerts on Windows DNS lookups where the queried name contains ufile.io, indicating potential exfiltration-related activity.
sigmaWindowslow2022-06-23Windows Process Execution: msdt.exe Launched with -cab Flag
Alerts when msdt.exe is started with the "-cab" argument, consistent with suspicious cabinet-based diagcab usage.
sigmaWindowsmedium2022-06-21Windows PowerShell: Execution of TroubleshootingPack Cmdlets (msdt-related usage)
Flags PowerShell script blocks invoking TroubleshootingPack with unattended answer-file arguments.
sigmaWindowsmedium2022-06-21Windows PowerShell Hotfix Enumeration via Win32_QuickFixEngineering
Detects PowerShell scripts enumerating installed hotfixes by querying Win32_QuickFixEngineering for HotFixID.
sigmaWindowsmedium2022-06-21Windows wmic.exe Used to Start or Stop Services
Alerts on wmic.exe command lines invoking startservice or stopservice via service calls.
sigmaWindowsmedium2022-06-20Windows WMIC Process Creation Recon for Unquoted Service Paths
Flags wmic.exe service queries requesting name/displayname/pathname/startmode to support unquoted service path reconnaissance.
sigmaWindowsmedium2022-06-20Windows Hotfix Inventory Recon via wmic.exe qfe
Detects wmic.exe executions with "qfe" used to enumerate installed Windows hotfixes.
sigmaWindowsmedium2022-06-20Windows CLI Enumeration of 3rd-Party Credential Registry Keys
Alerts when Windows processes use command-line queries to enumerate credential-containing third-party registry keys.
sigmaWindowsmedium2022-06-20Windows Dsacls.EXE Password Spraying Check via /user and /passwd
Flags dsacls.exe executions that specify both /user: and /passwd:, consistent with password spraying attempts.
sigmaWindowsmedium2022-06-20Windows: dsacls.exe used to grant potentially over-permissive access rights
Alerts on dsacls.exe commands using /G to grant wide or permissive ACL permissions.
sigmaWindowsmedium2022-06-20PowerShell WMI Service Enumeration for Unquoted Service Path Recon
Flags PowerShell WMI queries for Win32_Service fields to enumerate potential unquoted service path issues.
sigmaWindowsmedium2022-06-20Windows Registry: New W32Time TimeProvider DllName Values Set Under Services\W32Time\TimeProvider
Alerts on new or changed W32Time TimeProvider DllName registry values under Services\W32Time\TimeProvider.
sigmaWindowshigh2022-06-19Windows: Chromium-Based Browser Launched via Script Host with --load-extension
Flags Windows process creation where Chromium browsers are spawned with --load-extension= from common script/LOLBins parents.
sigmaWindowshigh2022-06-19Windows Chromium-Based Browser Launched With --load-extension Flag
Alerts when a Chromium-based browser starts with --load-extension= to load a custom extension.
sigmaWindowsmedium2022-06-19Windows File Events: Flag Files With Double Extensions (e.g., .docx.exe)
Alerts on Windows filenames that look like double extensions, including .rar.exe/.zip.exe masquerading patterns.
sigmaWindowshigh2022-06-19Windows: msdt.exe Loads sdiageng.dll via Image Load Events
Flags msdt.exe image-load events that load sdiageng.dll, a behavior commonly associated with DLL side-loading abuse.
sigmaWindowshigh2022-06-17Windows Process Creation: Sysinternals PsService (PsService*.exe) Execution
Alerts on execution of Sysinternals PsService (PsService*.exe) on Windows, which can support service discovery and tampering.
sigmaWindowsmedium2022-06-16