Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Office Startup Folder File Creation with Uncommon Extension
Detects unusual-extension files created in Word/Excel startup folders on Windows, potentially supporting automatic Office loading.
sigmaWindowshigh2022-06-05Windows rundll32 Locks Workstation via user32.dll LockWorkStation
Flags cmd-launched rundll32.exe calling user32.dll LockWorkStation to lock the user workstation.
sigmaWindowsmedium2022-06-04Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.
sigmaWindowslow2022-06-04Windows Process Creation: Renamed msdt.exe Execution
Flags Windows process creation where OriginalFileName is msdt.exe and the executable appears to be a renamed copy.
sigmaWindowshigh2022-06-03Python Process Spawning a Pretty TTY via pty.spawn on Windows
Flags Windows python executions whose command line imports pty and calls pty.spawn to create a pseudo-terminal.
sigmaWindowshigh2022-06-03Windows Process Creation: BrowserCore.exe Renamed Execution for Azure Token Theft
Flags renamed BrowserCore.exe executions by matching OriginalFileName while the process image ends with BrowserCore.exe.
sigmaWindowshigh2022-06-02Windows Process Creation: Remote.exe Execution
Alerts on execution of remote.exe on Windows, which can be abused via a WinDbg/SDK binary for stealthy remote execution.
sigmaWindowsmedium2022-06-02Windows Process Execution of F# Interpreters (Fsi.exe, FsiAnyCpu.exe)
Flags execution of F# interpreter binaries fsi.exe and fsianycpu.exe on Windows.
sigmaWindowsmedium2022-06-02Windows File Events: wmiexec Default Output File Creation (__1<9 digits>.<1-7 digits>)
Detects Windows file creation matching wmiexec default output filename patterns in admin share and drive paths.
sigmaWindowscritical2022-06-02Windows Office Startup Folder File Drop for Persistence via Office Documents
Alerts when Office documents/templates are created in Word/Excel startup folders on Windows, suggesting persistence attempts.
sigmaWindowshigh2022-06-02Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Alert when sdiagnhost.exe launches high-risk child processes like PowerShell or CMD, excluding selected benign-like command patterns.
sigmaWindowshigh2022-06-01Windows msdt.exe Execution with Suspicious Parent Process
Alerts when msdt.exe runs under common command-and-script or utility parent processes on Windows.
sigmaWindowshigh2022-06-01Windows Process Creation: wfc.exe Execution for Workflow Command-line Compiler Abuse
Alerts on execution of wfc.exe by matching process image and OriginalFileName in Windows process creation logs.
sigmaWindowsmedium2022-06-01VisualUiaVerifyNative.exe Execution on Windows
Alerts when VisualUiaVerifyNative.exe is launched on Windows, a potential application-control bypass binary.
sigmaWindowsmedium2022-06-01Windows Registry: Custom URL Protocol Handler Persistence via HKCR\ Protocol Registration
Alerts on HKCR registry set activity registering a new custom URL protocol handler, excluding Microsoft-style ms- protocols.
sigmaWindowsmedium2022-05-30Windows msdt.exe / ms-msdt Handler Arbitrary Command Execution Attempts
Alerts on Windows executions of msdt.exe with command-line indicators suggesting arbitrary command execution.
sigmaWindowshigh2022-05-29Windows Registry: OneDriveStandaloneUpdater.exe URL From UpdateOfficeConfig for Proxy Download
Alerts on registry settings that redirect OneDrive update URL retrieval from UpdateOfficeConfig for internet downloads.
sigmaWindowshigh2022-05-28PowerShell: Signed UtilityFunctions.ps1 Loading Managed DLL via Proxy Execution
Flags PowerShell command lines referencing UtilityFunctions.ps1 with RegSnapin usage consistent with managed DLL proxy execution.
sigmaWindowsmedium2022-05-28Windows: Pubprn.vbs Script Proxy Execution via script: Command Line
Flags command-line executions referencing Pubprn.vbs with 'script:' indicative of proxy script command execution on Windows.
sigmaWindowsmedium2022-05-28Windows PowerShell detects obfuscated Net.Webclient casing anomalies in command line
Alerts when PowerShell command lines contain encoded obfuscation patterns referencing Net.Webclient with anomalous casing.
sigmaWindowshigh2022-05-24