Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: ScreenConnect Client Service Spawning Suspicious Utility Commands
Alerts when ScreenConnect run.cmd leads to child processes like cmd.exe, PowerShell, curl, or other utilities.
sigmaWindowsmedium2022-02-25Windows process creation: CrackMapExec execution via characteristic command-line flags
Alerts on Windows process creation showing CrackMapExec-style command-line flags for local auth and module execution.
sigmaWindowshigh2022-02-25Windows MSExchangeMailboxReplication .aspx/.asp File Writes Indicating Web Shell Upload
Alerts when MSExchangeMailboxReplication.exe writes .asp or .aspx files on Windows, indicating potentially malicious server-side script drops.
sigmaWindowshigh2022-02-25Windows Registry: Disable CrashDump via CrashControl DWORD value
Alerts on registry changes that disable Windows crash dumps by writing 0x00000000 to CrashControl.
sigmaWindowsmedium2022-02-24Windows Scheduled Task Creation via schtasks with Suspicious Command-Line Patterns
Flags schtasks.exe /Create commands containing suspicious interpreter, encoding, hidden execution, or unusual path/script components.
sigmaWindowshigh2022-02-23Windows explorer.exe spawned with /NOUACCHECK flag for UAC bypass behavior
Alerts on explorer.exe executions that include /NOUACCHECK, indicating potential bypass of UAC checks for child processes.
sigmaWindowshigh2022-02-23Windows Schtasks.exe Task Creation Targeting Suspicious Paths or Env Variables
Alerts when schtasks.exe creates tasks whose target path/arguments reference suspicious folders or common environment variables.
sigmaWindowsmedium2022-02-21Windows CHCP Console Code Page Lookup Triggered From cmd.exe
Flags cmd.exe-launched chcp.com executions likely used to query system code page/locale for discovery.
sigmaWindowsmedium2022-02-21Suspicious Reset-ComputerMachinePassword Usage via PowerShell on Windows
Detects PowerShell executions of Reset-ComputerMachinePassword that may indicate attempts to alter domain computer account authentication.
sigmaWindowsmedium2022-02-21Windows Process Execution of Tor or Tor Browser (tor.exe / Firefox-based)
Flags Windows execution of tor.exe or Tor Browser’s bundled Firefox from the expected installation path.
sigmaWindowshigh2022-02-20Windows Sysmon DNS Query to .onion or Tor Gateway Domains
Alerts when Windows Sysmon DNS queries target .onion or Tor gateway/proxy-related domain suffixes.
sigmaWindowshigh2022-02-20Windows DNS Client Query for .onion and Tor-related Domains
Alerts on Windows DNS queries resolving .onion and related Tor/hidden-service domains.
sigmaWindowshigh2022-02-20Windows Firewall Settings Change Events (Windows Firewall/Defender Firewall-AS)
Alert on Windows Firewall/Defender firewall setting changes using Events 2002, 2003, 2008, 2082, and 2083.
sigmaWindowslow2022-02-19Windows Defender Firewall Reset to Default Configuration (Firewall-as Service)
Flags Windows where Windows Defender Firewall is reset to default settings via firewall-as events.
sigmaWindowslow2022-02-19Windows Defender Firewall Service Failed to Load Group Policy (Event ID 2009)
Alert on Event ID 2009 when the Windows Defender Firewall service cannot load Group Policy.
sigmaWindowslow2022-02-19Windows Firewall exception rule deleted (Windows Firewall/Defender) EventID 2006/2052
Flags deletion of Windows Defender Firewall exception rules using EventID 2006 or 2052 with modifying application context.
sigmaWindowsmedium2022-02-19Windows Firewall: New Exception List Rule Added (Uncommon Defender Firewall Event 2004/2071/2097)
Alerts on Windows Firewall exception rule additions (Event IDs 2004/2071/2097), excluding common benign paths.
sigmaWindowsmedium2022-02-19Windows Process Creation: wlrmdr.exe with -u Flag or Uncommon Child Process Execution
Flags wlrmdr.exe launched with -u or uncommon children spawned with specific flags, using process creation telemetry.
sigmaWindowsmedium2022-02-16Windows Process Command-Line Dosfuscation Pattern Detection (Potential Obfuscation)
Alerts on Windows command lines containing known dosfuscation-style obfuscation patterns.
sigmaWindowsmedium2022-02-15Windows: Rundll32 Executing Registered COM Local Servers via Command-Line { }
Flags rundll32.exe launching COM local servers using -sta/-localserver with braced arguments.
sigmaWindowshigh2022-02-13