Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Service Control Manager: HackTool Service Installation or Start via Suspicious Service Names
Detects Windows service creation/start events tied to hacktool-like service names or ImagePath indicators.
sigmaWindowshigh2022-03-21Windows Registry Policy Modification for Explorer UI Function Disabling
Flags Windows Explorer policy registry value writes (DWORD 0x1) that disable Explorer functions or UI elements.
sigmaWindowsmedium2022-03-18Windows Registry Defense Impairment via Explorer Hide* Policy Values
Flags registry set events that change Explorer hide-related DWORD values under Windows policy keys to impair user visibility.
sigmaWindowsmedium2022-03-18Windows Registry Policy Change to Disable/Impair Internal Tools and UI Features
Detects registry policy edits that disable Windows tools/features or alter related system behavior via specific DWORD values.
sigmaWindowsmedium2022-03-18Windows Service Installation via Scripted ImagePath Indicators (Event 7045)
Identifies suspicious Windows service installations that embed script host execution via Event ID 7045 ImagePath patterns.
sigmaWindowshigh2022-03-18Windows Service Installation with Suspicious ProgramData/Root Executable Image Paths
Flags Windows service installs (Event 7045) that reference suspicious EXE paths in ProgramData or directly under C:\.
sigmaWindowshigh2022-03-18Windows Service Installation with PowerShell Download and Hidden Execution
Alerts on Windows service creation (7045) with ImagePath patterns indicating hidden/staged command execution.
sigmaWindowshigh2022-03-18Windows Registry Run Key Entries Containing PowerShell Execution Strings
Alerts when registry Run key value data contains PowerShell launch or encoded download/execution strings on Windows.
sigmaWindowsmedium2022-03-17Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Flags web server processes spawning child commands consistent with credential dumping, exfiltration, and privilege changes.
sigmaWindowshigh2022-03-17Windows PktMon.exe Process Execution (pktmon.exe / PktMon.exe)
Alerts on Windows executions of PktMon.exe based on process creation image name and OriginalFileName.
sigmaWindowsmedium2022-03-17Windows PowerShell: Suspicious Process Discovery Using Get-Process
Alerts when PowerShell script blocks contain Get-Process, indicating local process discovery activity.
sigmaWindowslow2022-03-17PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
sigmaWindowslow2022-03-17Windows PowerShell Directory Enumeration via Get-ChildItem and Output Redirection
Flags PowerShell directory enumeration patterns using Get-ChildItem, error suppression, and appended output to a file.
sigmaWindowsmedium2022-03-17Windows PowerShell Active Directory Group Enumeration via Get-AdGroup Cmdlet
Flags PowerShell script blocks that call Get-ADGroup with -Filter to enumerate Active Directory groups.
sigmaWindowslow2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
sigmaWindowslow2022-03-17PowerShell Get-ADUser Enumeration Using UserAccountControl DONT_REQ_PREAUTH Flag
Flags Get-ADUser PowerShell scripts enumerating accounts by UserAccountControl DONT_REQ_PREAUTH (4194304).
sigmaWindowsmedium2022-03-17Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
sigmaWindowshigh2022-03-16Windows Remote Thread Creation Targeting Uncommon System Image Processes
Alert on Windows remote thread creation events targeting a predefined list of uncommon processes by image path.
sigmaWindowsmedium2022-03-16Windows schtasks.exe Create Executes File from AppData\Local
Alerts on schtasks.exe creating tasks that run payloads from C:\Users\<user>\AppData\Local.
sigmaWindowshigh2022-03-15Windows Process Creation: Suspicious for/foreach Scan Loop with nslookup or ping
Alerts on Windows command lines using for/foreach loops that also run nslookup or ping, consistent with host scanning.
sigmaWindowsmedium2022-03-12