Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: KrbRelay.exe Kerberos Relay Tool Execution
Flags Windows process creation for KrbRelay.exe with Kerberos relaying-related command-line arguments.
sigmaWindowshigh2022-04-27Windows Hacktool Execution via PE Metadata Company Field
Flags execution of Windows binaries with PE Company metadata set to "Cube0x0", even when renamed.
sigmaWindowshigh2022-04-27Windows UAC Bypass via Event Viewer RecentViews File Creation
Alerts on suspicious file events to Event Viewer RecentViews paths that may indicate a Windows UAC bypass attempt.
sigmaWindowshigh2022-04-27Windows: Detect .SCR screen saver file creation outside common system directories
Alerts on creation of .scr screen saver files in unusual locations on Windows.
sigmaWindowsmedium2022-04-27Windows Successful Local Kerberos Logon to Built-in Administrator (Possible Privilege Escalation)
Alert on successful local (127.0.0.1) Kerberos logons targeting the built-in Administrator SID for potential privilege escalation.
sigmaWindowshigh2022-04-27Windows: Detect KrbRelayUp.exe HackTool Process Execution
Flags Windows process executions of KrbRelayUp.exe with relay/domain and SCM spawn command-line patterns.
sigmaWindowshigh2022-04-26Windows LsaSrv Events Indicating NTLMv1 Logon Between Client and Server
Flags LsaSrv events 6038/6039 showing NTLMv1 authentication between client and server on Windows.
sigmaWindowsmedium2022-04-26Windows Sysmon Application Popup Crash (Event ID 26)
Flags Application Popup events reporting sysmon64.exe/sysmon.exe “Application Error” (Event ID 26).
sigmaWindowshigh2022-04-26Windows msiexec.exe Command Line Loading a DLL and Calling DllUnregisterServer
Alert when msiexec.exe runs with -z and a .dll on the command line, consistent with DLL DllUnregisterServer execution.
sigmaWindowsmedium2022-04-24PowerShell WMI Win32_Product MSI Installation via Invoke-CimMethod
Flags PowerShell using WMI Win32_Product via Invoke-CimMethod to invoke an MSI install.
sigmaWindowsmedium2022-04-24Windows: File Creation of Get-Variable.exe in PowerShell WindowsApps Path
Alerts on creation of Get-Variable.exe in Local\Microsoft\WindowsApps, a potential cmdlet-path hijack.
sigmaWindowshigh2022-04-23Windows Remote Thread Created in KeePass.exe
Flags remote thread creation targeting KeePass.exe, a possible indicator of credential theft.
sigmaWindowshigh2022-04-22Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Alerts on rundll32 launching the Windows Key Manager (keymgr / KRShowKeyMgr), a potential credential access step.
sigmaWindowshigh2022-04-21Windows process contacting Dropbox API from non-Dropbox executables
Alerts when a non-Dropbox executable makes initiated connections to Dropbox API endpoints on Windows.
sigmaWindowshigh2022-04-20Windows Process Creation: msiexec.exe Embedding Spawned by PowerShell/cmd/pwsh
Alerts when cmd/powershell launches msiexec.exe with -Embedding, a proxy execution pattern.
sigmaWindowsmedium2022-04-16Windows Registry: Delete SD Value Under Schedule\TaskCache\Tree to Impair Scheduled Task Visibility
Detects deletion of the SD registry value under Schedule\TaskCache\Tree, which can impair scheduled task visibility.
sigmaWindowsmedium2022-04-15Windows schtasks.exe scheduled task creation from suspicious folders
Alerts on schtasks.exe /create using PowerShell/cmd and suspicious folder paths like ProgramData.
sigmaWindowshigh2022-04-15Windows Network Connections Initiated by Eqnedt32.EXE
Identifies outbound network connections started by eqnedt32.exe on Windows.
sigmaWindowshigh2022-04-14PowerShell Hyper-V Cmdlets Execution via Script Blocks (New-VM, Set-VMFirmware, Start-VM)
Alerts when PowerShell script blocks use Hyper-V VM creation or start cmdlets (New-VM, Set-VMFirmware, Start-VM).
sigmaWindowsmedium2022-04-09Windows Credential Manager Enumeration via VaultCmd.exe /listcreds
Flags VaultCmd.exe executions that enumerate saved Windows Credential Manager entries using /listcreds.
sigmaWindowsmedium2022-04-08