Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows OpenConsole LOLBIN Execution via Process Creation
Alerts when OpenConsole.exe runs (outside a specific Windows Terminal path), potentially used to bypass application whitelisting.
sigmaWindowsmedium2022-06-16Windows Registry: Enable ScriptedDiagnostics TurnOffCheck DWORD via Policies
Flags registry policy enabling ScriptedDiagnostics TurnOffCheck (DWORD 0x00000001) on Windows.
sigmaWindowsmedium2022-06-15Windows: Execution of Pcalua.exe with -a Argument
Flags Pcalua.exe executions containing " -a" that may indicate indirect command execution on Windows.
sigmaWindowsmedium2022-06-14Windows forfiles.exe Execution with /c Flag Command Proxying
Flags forfiles.exe executions that include the /c flag, indicating potential indirect command execution.
sigmaWindowsmedium2022-06-14Windows conhost.exe Path Traversal in Process Command Line
Detects Windows conhost.exe command lines containing '/../../' path traversal indicators.
sigmaWindowshigh2022-06-14Windows msdt.exe execution using PCWDiagnostic.xml answer file
Alerts on msdt.exe launched with PCWDiagnostic.xml and an answer-file argument, excluding cases from pcwrun.exe.
sigmaWindowshigh2022-06-13Windows: Indirect execution of pcwrun.exe using path traversal-style command line content
Detects pcwrun.exe spawning with '../' in the command line, indicating potential indirect execution abuse.
sigmaWindowshigh2022-06-13Windows Registry Custom File Open Handler Executes PowerShell
Alerts when a registry shell open handler is created to run PowerShell with -command.
sigmaWindowshigh2022-06-11Windows Process: Notepad++ GUP (GUP.exe) Download Execution via -unzipTo and URL
Detects Notepad++ GUP.exe downloading over HTTP initiated by a non-Notepad++ parent process.
sigmaWindowshigh2022-06-10Windows: GUP Utility Spawns Commands from Explorer via Notepad++ Updater
Flags Notepad++ updater-launched GUP activity that causes explorer.exe to execute with notepad++ in the command line.
sigmaWindowsmedium2022-06-10Windows: New Notepad++ plugins DLL written outside gup.exe
Alerts on creation of Notepad++ plugin DLLs by a process other than gup.exe, suggesting possible persistence via custom plugins.
sigmaWindowsmedium2022-06-10Windows BITS Client Job Downloads From Uncommon Remote TLDs
Alerts on BITS transfers (EventID 16403) to remote domains with uncommon or suspicious TLD patterns.
sigmaWindowsmedium2022-06-10Windows Process Execution via Squirrel.exe Proxy Arguments
Identifies Windows executions of Squirrel.exe/Update.exe that use processStart-style arguments to launch other processes.
sigmaWindowsmedium2022-06-09Windows Process: Squirrel.exe Using Download/Update Flags to Fetch Files
Alert on Squirrel.exe/update.exe runs with --download/--update flags and HTTP in the command line.
sigmaWindowsmedium2022-06-09Windows Process Creation: Mftrace.exe Child Process Execution
Alerts on child processes spawned by Mftrace.exe, which can be abused to execute arbitrary binaries on Windows.
sigmaWindowsmedium2022-06-09Windows: Process creation involving VSIISExeLauncher.exe with -p and -a arguments
Flags Windows launches of VSIISExeLauncher.exe with "-p" and "-a" parameters, consistent with potential arbitrary binary execution.
sigmaWindowsmedium2022-06-09Windows: Adplus.exe Execution with Memory Dump and Command Options
Alerts on Windows executions of Adplus.exe with memory-dump and inline command parameters.
sigmaWindowshigh2022-06-09Windows File Creation of .diagcab Packages
Alerts on newly created Windows .diagcab files that may indicate malicious packaging or exploitation.
sigmaWindowsmedium2022-06-08Windows: ISO Image Opened by Archiver Utilities (WinRAR/7-Zip/PeaZIP)
Alerts when WinRAR/7-Zip/PeaZIP spawns ISO image tools, a pattern consistent with archive-delivered ISO payloads.
sigmaWindowshigh2022-06-07Windows Process Creation: Renamed Plink (plink.exe) with SSH Port Forwarding Flags
Alerts on renamed Plink executions using SSH port forwarding flags in Windows process creation logs.
sigmaWindowshigh2022-06-06