Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Doppelganger (Doppelanger.exe) LSASS Dump Tool Execution
Alerts on Windows execution of Doppelganger.exe with matching IMPHASH values associated with LSASS dumping.
sigmaWindowshigh2025-07-01Windows Process Creation: Command-Line Kerberos Coercion Signature via DNS SPN Spoofing
Alerts on Windows command lines containing 'UWhRCA' and 'BAAAA', a signature tied to Kerberos coercion via spoofed credential targeting.
sigmaWindowshigh2025-06-20Windows DNS Query with Kerberos Coercion Signature via DNS Object SPN Spoofing
Alerts on Windows DNS queries containing a base64-like credential target signature linked to Kerberos coercion via DNS spoofing.
sigmaWindowshigh2025-06-20Windows AD DNS Record Modification Indicators for Kerberos Coercion via SPN DNS Spoofing
Alerts on AD MicrosoftDNS DNS node changes whose DN contains a CREDENTIAL_TARGET_INFORMATION base64 marker tied to Kerberos coercion.
sigmaWindowshigh2025-06-20Windows DLL Load Trusted Path Bypass via Spoofed Directory Paths with Extra Space
Flags Windows DLL loads from spoofed "C:\Windows \\System32"-style paths with an extra space to indicate trusted-path bypass attempts.
sigmaWindowshigh2025-06-17Windows Process Information Discovery via Registry Queries (reg.exe/powershell)
Flags reg.exe and PowerShell registry queries used to enumerate OS, Defender, installed apps, timezone, and services.
sigmaWindowslow2025-06-12Windows Process Creation: SharpSuccessor.exe Execution with Impersonation Parameters
Alerts on SharpSuccessor.exe command-line patterns indicative of Windows privilege escalation attempts.
sigmaWindowshigh2025-06-06RegAsm.exe Process Execution Missing Command-Line and Assembly Path (Windows)
Alert on RegAsm.exe process creation when the command line lacks typical Regasm flags or file parameters.
sigmaWindowslow2025-06-04Windows Event Log: MSSQLSERVER$AUDIT alerts on DROP/ TRUNCATE destructive SQL statements
Flags audited MSSQL transactions that include DROP TABLE, DROP DATABASE, or TRUNCATE TABLE.
sigmaWindowsmedium2025-06-04Windows DNS Queries to Malware Hosting and URL Shortener Domains
Alert on Windows DNS queries to domains tied to URL shorteners and malware hosting services.
sigmaWindowsmedium2025-06-02Windows: TacticalRMM Agent Installed with API/Auth Flags Pointing to Remote RMM Server
Alerts when TacticalRMM agent starts with --api/--auth and identity flags consistent with connecting to a configured remote RMM server.
sigmaWindowsmedium2025-05-29Windows PowerShell Obfuscated COM MSI Installation via WindowsInstaller.Installer
PowerShell spawning that uses WindowsInstaller.Installer COM with obfuscated strings to call InstallProduct and suppress UI.
sigmaWindowshigh2025-05-27Windows vshadow.exe Proxy Execution via -exec Script/Command
Alerts when vshadow.exe is run with -exec, which can proxy execution of a script or command after shadow copy creation.
sigmaWindowsmedium2025-05-26Windows: New-ADServiceAccount Creates Delegated Service Account in Target OUs
Alerts on PowerShell runs of New-ADServiceAccount to create a delegated service account with -CreateDelegatedServiceAccount and -path.
sigmaWindowsmedium2025-05-24Windows PowerShell Modifies dMSA msDS-ManagedAccountPrecededByLink Attributes
Flags PowerShell script content modifying msDS-ManagedAccountPrecededByLink (dMSA link attributes) via AD link changes.
sigmaWindowslow2025-05-24PowerShell dMSA Service Account Creation in Target OUs via New-ADServiceAccount
Alerts on PowerShell creating a delegated service account via New-ADServiceAccount with -CreateDelegatedServiceAccount and -path.
sigmaWindowsmedium2025-05-24Windows reg.exe Registry Save/Export of Third-Party Credential Paths
Alerts on reg.exe save/export commands targeting registry keys tied to third-party credential data.
sigmaWindowshigh2025-05-22Windows: Deno writes files from remote HTTPS content into AppData
Alerts when Deno writes to user AppData while using remote HTTPS download-style paths.
sigmaWindowslow2025-05-22Windows File Access to Browser Credential Storage by Non-Browser Processes
Flags non-browser processes reading common browser credential storage files on Windows, indicating potential credential theft.
sigmaWindowslow2025-05-22Windows Security: Kerberos TGT requests with PreAuthType=0 and RC4-HMAC (0x17) to krbtgt
Alerts on krbtgt TGT requests using RC4-HMAC with pre-authentication disabled (PreAuthType=0), consistent with AS-REP roasting attempts.
sigmaWindowsmedium2025-05-22