Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell Process Command Lines With Encoded Command Flags
Alerts on PowerShell (pwsh) command lines using encoded command flags and encoded-looking substrings, excluding gc_worker.exe-related activity.
sigmaWindowshigh2022-05-24Windows: Jlaive In-Memory Assembly Execution via Copied Batch Executable
Detects chained cmd/.bat staging that uses xcopy plus PowerShell/pwsh and attrib +h/+s to run a .bat.exe payload associated with Jlaive.
sigmaWindowsmedium2022-05-24Windows: rundll32.exe launched by explorer.exe parent process
Alerts when explorer.exe spawns rundll32.exe with specific command-line characteristics on Windows.
sigmaWindowsmedium2022-05-21Windows PowerShell Script Proxy Execution via CL_mutexverifiers.ps1
Alerts on PowerShell being launched with CL_mutexverifiers that proxies additional script execution.
sigmaWindowsmedium2022-05-21PowerShell Assembly Loading via CL_LoadAssembly.ps1 Functions
Alerts on PowerShell command lines that call LoadAssemblyFromPath/LoadAssemblyFromNS in CL_LoadAssembly.ps1 context.
sigmaWindowsmedium2022-05-21Windows AnyDesk Executed from Suspicious Directory
Alerts on AnyDesk execution from non-standard folders on Windows, indicating potential remote access abuse.
sigmaWindowshigh2022-05-20Windows PowerShell Base64 Encoded Commands Containing Invoke- ( -e )
Flags PowerShell executions using the -e encoded command flag with Base64 patterns consistent with an Invoke- call.
sigmaWindowshigh2022-05-20Windows grpconv Utility Execution with Output Option
Alerts on Windows process command lines invoking GrpConv with -o, potentially for .grp conversion or persistence.
sigmaWindowshigh2022-05-19Windows Office Applications Downloading Files via HTTP/HTTPS
Detects Office binaries invoked with command lines containing http/https, indicating potential arbitrary file download.
sigmaWindowshigh2022-05-17Windows Event Log Cleared (EventID 104, Microsoft-Windows-Eventlog)
Alerts when Microsoft-Windows-Eventlog reports Event ID 104 for core event log channels, indicating log clearing.
sigmaWindowshigh2022-05-17Windows: Process creation of TTDInject.exe (ttdinject.exe) for Time Travel Debugging
Alerts on Windows process creation for ttdinject.exe (TTDInject.EXE), a time travel debugging component.
sigmaWindowsmedium2022-05-16Windows gpscript.exe Executes Group Policy Logon/Startup Scripts
Flags gpscript.exe running with /logon or /startup, suggestive of Group Policy script execution abuse.
sigmaWindowsmedium2022-05-16Windows IEExec.EXE Download-and-Execute via Process Creation
Flags IEExec.exe executions that reference HTTP/HTTPS URLs for download-and-execute behavior.
sigmaWindowshigh2022-05-16Windows: File Download via CertOC.exe Using -GetCACAPS HTTP
Flags CertOC.exe launched with -GetCACAPS and an http URL, indicating a remote file retrieval attempt.
sigmaWindowsmedium2022-05-16Windows Remote Thread Creation via Ttdinject.exe Proxy
Alerts on Windows create-remote-thread events initiated by Ttdinject.exe used as a proxy.
sigmaWindowshigh2022-05-16Windows Process Creation: reg.exe Adds Winlogon SpecialAccounts Userlist Value 0
Flags reg.exe command lines that add SpecialAccounts Userlist with /d 0 to hide accounts from the logon screen.
sigmaWindowsmedium2022-05-14Windows Service Creation for KrbRelayUp (KrbSCM)
Flags creation of the KrbSCM Windows service, a known KrbRelayUp installation artifact.
sigmaWindowshigh2022-05-11Windows PowerShell Execution of Obfuscated One-Liner for In-Memory Module Download
Alerts on Windows PowerShell one-liners containing an obfuscated in-memory download/execute pattern from an HTTP URL.
sigmaWindowshigh2022-05-09Windows: WerFault.exe/wer.dll File Creation in Uncommon Locations
Alerts on newly created WerFault.exe or wer.dll in non-standard locations, suggesting potential DLL hijacking activity.
sigmaWindowsmedium2022-05-09Windows Security Event 5379: Opened Password-Protected ZIP from Outlook Attachment
Flags Windows events where a password-protected ZIP is opened from Outlook Temporary Internet Files.
sigmaWindowshigh2022-05-09