Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Security: Password-Protected ZIP Opened with Suspicious Filename Indicators
Alerts when Windows opens password-protected ZIP contents with filenames commonly tied to invoices, orders, payments, and deliveries.
sigmaWindowshigh2022-05-09Windows Security Event 5379: Password-Protected ZIP Opened
Flags Windows EventID 5379 indicating a password-protected ZIP archive was opened.
sigmaWindowsmedium2022-05-09Windows: ie4uinit.exe Used from Non-Standard Current Directory
Flags ie4uinit.exe runs whose CurrentDirectory is outside expected system paths, indicating potential LOLBIN misuse.
sigmaWindowsmedium2022-05-07Windows Process Creation: Ilasm.EXE Used to Compile IL to EXE/DLL
Alerts when Ilasm.EXE is run with /exe or /dll to compile IL into a Windows binary.
sigmaWindowsmedium2022-05-07Windows Process Creation: Cobalt Strike module/command strings entered in cmd.exe
Alerts when cmd.exe command lines include Cobalt Strike module/command strings.
sigmaWindowshigh2022-05-06Windows Process Command Line: Accidental Cobalt Strike Commands in cmd.exe
Flags cmd.exe executions whose command lines include known Cobalt Strike command terms.
sigmaWindowshigh2022-05-06Windows Process Creation: Suspicious Child Processes Spawned by regsvr32.exe
Alerts when regsvr32.exe spawns suspicious child processes like PowerShell, mshta, or scripting utilities.
sigmaWindowshigh2022-05-05Windows: Registry Set by Rundll32 for Screen Saver Execution via SCRNSAVE.EXE
Flags Windows registry sets where Rundll32 points SCRNSAVE.EXE to a .scr file.
sigmaWindowsmedium2022-05-04Windows Rundll32 Calls DavSetCookie for NTLM Coercion via Spoolss/Srvsvc
Detects rundll32.exe launching davclnt.dll DavSetCookie with HTTP and spoolss/srvsvc pipe parameters associated with NTLM coercion.
sigmaWindowshigh2022-05-04Windows Registry: Service configured with image path in suspicious public/temp folders
Detects Windows service ImagePath pointing to Users\Public, Perflogs, ADMIN$, or Temp based on registry_set events.
sigmaWindowshigh2022-05-02Windows: PrintBrm.exe ZIP extraction or creation via command-line parameters
Flags PrintBrm.exe executions that include '-f' and '.zip', consistent with ZIP creation or extraction behavior.
sigmaWindowshigh2022-05-02Windows JScript Compiler (jsc.exe) Process Execution
Identifies execution of jsc.exe (JScript Compiler) from Windows process creation logs.
sigmaWindowslow2022-05-02Windows Process Creation: gpresult.exe Group Policy (RSoP) Discovery (/z /v)
Flags process executions of gpresult.exe that request RSoP details using /z and /v on Windows.
sigmaWindowsmedium2022-05-01Windows svchost.exe RDP (3389) Connections to HTTP/HTTPS Ports 80 or 443
Alerts when svchost.exe initiates from TCP 3389 to destination ports 80 or 443, consistent with possible RDP tunneling over web ports.
sigmaWindowshigh2022-04-29Windows: Detect ngrok Traffic Forwarded to Local RDP Port via TerminalServices Logs
Detects suspicious ngrok usage that forwards to the local RDP port using Windows TerminalServices-LocalSessionManager EventID 21.
sigmaWindowshigh2022-04-29Windows rundll32.exe executing InstallScreenSaver via desk.cpl SCR File
Detects rundll32.exe launches with InstallScreenSaver behavior via desk.cpl, a screensaver execution technique.
sigmaWindowsmedium2022-04-28Windows Microsoft Sync Center (mobsync.exe) Network Connections to Public IPs
Alerts when mobsync.exe makes outbound connections to destination IPs outside private/local ranges.
sigmaWindowsmedium2022-04-28Windows: Copying Executable or DLL Files into Default GPO Policies Folder
Alerts when .exe/.dll files are created in the default GPO storage folder path.
sigmaWindowsmedium2022-04-28Windows: Files created by Microsoft Sync Center (mobsync.exe) with .dll/.exe extensions
Flags .dll and .exe files created by mobsync.exe on Windows.
sigmaWindowsmedium2022-04-28Windows: rundll32.exe spawning explorer.exe child process (shell32.Control_RunDLL)
Alerts on rundll32.exe spawning explorer.exe, an uncommon child process pattern that may indicate stealthy execution via shell components.
sigmaWindowshigh2022-04-27