Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: SQLite Access to Firefox Profile Databases
Alerts when Windows runs SQLite tooling to query Firefox profile DBs like cookies.sqlite or places.sqlite.
sigmaWindowshigh2022-04-08Windows Task Scheduler persistence using svchost-launched PowerShell with hidden/Bypass flags
Alerts on svchost.exe Schedule tasks spawning PowerShell with hidden window and execution policy bypass flags.
sigmaWindowshigh2022-04-08Windows PowerShell execution from C:\Users\Public
Flags PowerShell command lines that reference C:\Users\Public, indicating likely script execution from a common public staging area.
sigmaWindowshigh2022-04-06Windows Process Creation: Node.js Executions from Adobe Creative Cloud
Flags Windows executions of Adobe Creative Cloud’s bundled node.exe, excluding typical JS resource paths.
sigmaWindowsmedium2022-04-06Windows: Detect Suspicious DumpMinitool.exe Execution via Process Command-Line
Alerts on suspicious command-line usage of DumpMinitool.exe on Windows, leveraging process creation Image, OriginalFileName, and command-line text.
sigmaWindowshigh2022-04-06Windows: Detect DumpMinitool.exe Execution for Process Memory Dumping
Identifies Windows executions of DumpMinitool.exe variants with dump options via process creation telemetry.
sigmaWindowsmedium2022-04-06Windows Security: Outgoing Logon (LogonType 9) Using New Credentials (4624)
Flags Windows 4624 LogonType 9 events where new credentials are used for authentication.
sigmaWindowslow2022-04-06Windows Registry: New Root CA or AuthRoot Certificates Added to Certificate Stores
Alerts on registry certificate-store writes adding new Root/CA/AuthRoot certificates as binary blobs.
sigmaWindowsmedium2022-04-04Windows Registry Key Change Disabling System Restore
Detects registry writes that disable Windows System Restore via policy/config keys set to DWORD 0x00000001.
sigmaWindowshigh2022-04-04Windows Registry Service Persistence via SafeBoot Control Keys
Flags Windows registry writes that configure a service to load in Safe Mode (SafeBoot Minimal/Network).
sigmaWindowshigh2022-04-04Windows PowerShell User Discovery via Current Username APIs
Alerts on PowerShell script blocks that retrieve the current username or user identity using common environment/.NET calls.
sigmaWindowslow2022-04-04Windows Registry Key Changes Disabling PowerShell Logging for Current User
Detects registry changes that disable PowerShell module/script logging and transcription by setting logging keys to DWORD 0.
sigmaWindowshigh2022-04-02Windows Registry Change Disabling Hidden and System File Display
Detects registry writes that disable Windows Explorer showing hidden/system files by setting Hidden and ShowSuperHidden to 0x0.
sigmaWindowsmedium2022-04-02Windows PowerShell: Suspicious GetTypeFromCLSID and ShellExecute usage
Flags PowerShell script blocks that use GetTypeFromCLSID followed by ShellExecute.
sigmaWindowsmedium2022-04-02Windows fsutil.exe Drive Enumeration via Process Execution
Flags fsutil.exe process launches with command lines referencing connected drive enumeration.
sigmaWindowslow2022-03-29Windows PowerShell IEX Invocation Patterns in Process Creation Command Lines
Alerts on suspicious PowerShell command lines that pipe or otherwise invoke IEX and may include Base64 decoding.
sigmaWindowshigh2022-03-24Windows PowerShell Download and Execution Cradles
Flags PowerShell commands that download remote content and immediately execute it using IEX/Invoke-Expression.
sigmaWindowshigh2022-03-24Windows: reg.exe Registry Tampering of Windows Defender Policy Keys
Detects reg.exe adding Defender DWORD policy values to disable or suppress multiple protection features via Windows registry.
sigmaWindowshigh2022-03-22Windows LSA PPL Protection Setting Modification via reg.exe or PowerShell Command Line
Flags Windows command lines that alter LSA PPL-related Control\Lsa registry settings using reg.exe/PowerShell property changes.
sigmaWindowsmedium2022-03-22Windows Suspicious Parent Processes: Unusual Child Creation by System Utilities
Alerts when predefined suspicious Windows parent executables spawn unusual or unrecognized child processes.
sigmaWindowshigh2022-03-21