Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
sigmaWindowshigh2022-03-12Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
sigmaWindowshigh2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
sigmaWindowshigh2022-03-11Windows Process Creation: OfflineScannerShell.exe mpclient.dll DLL Sideloading Risk
Detects OfflineScannerShell.exe launched with an unexpected current directory that could enable mpclient.dll sideloading.
sigmaWindowsmedium2022-03-06Windows Process Creation: Replace.exe with -a argument
Detects Replace.exe executions that include the -a argument, which may be used for file replacement.
sigmaWindowsmedium2022-03-06Windows Suspicious UltraVNC Command Line With Auto-Reconnect Flags
Alerts on UltraVNC execution using -autoreconnect with -connect and -id in the Windows command line.
sigmaWindowshigh2022-03-04PowerShell Base64 Encoded MpPreference Command Lines for Windows Defender Modification
Detects PowerShell Base64 command lines referencing Add-MpPreference/Set-MpPreference to modify Microsoft Defender AV settings.
sigmaWindowshigh2022-03-04Windows Hacktool Execution Flagged by Imphash in Process Creation
Alerts on Windows process executions where the import hash matches known hacktool binaries, even if renamed.
sigmaWindowscritical2022-03-04Windows PowerShell: Disable Microsoft Defender Scanning via Set-MpPreference
Flags PowerShell commands that disable Microsoft Defender scanning/protection settings using Set-MpPreference, including encoded variants.
sigmaWindowshigh2022-03-03Windows: fsutil SymlinkEvaluation behavior modification via command line
Alerts on fsutil commands from cmd/PowerShell that change NTFS SymlinkEvaluation behavior, potentially enabling remote symlink access.
sigmaWindowsmedium2022-03-02Windows Process Creation: Base64-Obfuscated .NET Reflection Assembly Load Call
Alerts on command lines containing Base64-encoded obfuscation for .NET reflection assembly load calls.
sigmaWindowshigh2022-03-01Windows PowerShell: Base64 Encoded Reflective .NET Assembly Load
Flags PowerShell command lines containing Base64 fragments consistent with reflective .NET Assembly.Load usage.
sigmaWindowshigh2022-03-01Windows BITS Transfer Jobs Downloading Files with Suspicious Extensions
Flags Windows BITS transfers saving local files with high-risk script/executable extensions while excluding common benign patterns.
sigmaWindowsmedium2022-03-01Windows BITS Job Creation Triggered by PowerShell
Flags new BITS job creation on Windows when initiated by PowerShell (Event ID 3).
sigmaWindowslow2022-03-01Windows BITS job created by bitsadmin.exe (BITS Client EventID 3)
Alerts on new BITS job creation when bitsadmin.exe triggers it (BITS-Client EventID 3).
sigmaWindowslow2022-03-01Windows PowerShell CommandLine downloads and executes via WebClient with IEX or DownloadFile
Alerts on PowerShell command lines that use WebClient downloads combined with IEX or DownloadFile, typical of staged payload execution.
sigmaWindowshigh2022-02-28Windows: Suspicious Process Spawn by Outlook Parent
Alerts on Windows process launches where Outlook.exe spawns known high-risk command execution binaries.
sigmaWindowshigh2022-02-28Windows Registry: Enable Microsoft DDE in Word or Excel Security Settings
Detects registry changes that enable or permit DDE server launch/lookup for Word or Excel.
sigmaWindowsmedium2022-02-26Suspicious wuauclt.exe Process Creation on Windows with Empty Command-Line Flags
Alert on Windows Update Agent wuauclt.exe launches that have command lines ending with no flags/arguments.
sigmaWindowshigh2022-02-26Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Alerts on processes launched from \Users\Public that execute common scripting/shell binaries or command-line markers.
sigmaWindowshigh2022-02-25