Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: ScreenConnect Service Execution
Alerts on Windows executions identified as ScreenConnect service/product/company strings, indicating potential remote access C2 activity.
sigmaWindowsmedium2022-02-13Windows: Process creation matching GoTo Opener (LogMeIn) for remote access tooling
Alerts on Windows process execution identified as “GoTo Opener” by LogMeIn, which may indicate remote access tool use.
sigmaWindowsmedium2022-02-13Windows: reg.exe Adds Windows Defender Exclusion Paths via Registry Value Update
Detects reg.exe commands that modify Windows Defender/Microsoft Antimalware exclusion path registry entries.
sigmaWindowsmedium2022-02-13Windows esentutl.exe Browser Data Collection via -r and WebCache path
Flags esentutl.exe runs with -r and WebCache references, indicating potential browser data collection.
sigmaWindowsmedium2022-02-13Windows File Creation of ScreenConnect Temporary Installation Artefact
Flags Windows file events referencing temporary ScreenConnect artefacts under the \Bin\ScreenConnect.* path.
sigmaWindowsmedium2022-02-13GoToAssist Temporary File Drop in Windows Temp Directory
Flags creation of GoToAssist Remote Support Expert temp installation artefacts under Windows AppData\Temp.
sigmaWindowsmedium2022-02-13Windows schtasks Creates Registry-Backed Base64 PowerShell Payload via Encoded Command
Flags schtasks.exe scheduling that triggers PowerShell to decode a base64 payload pulled from Windows Registry.
sigmaWindowshigh2022-02-12Windows reg.exe Used to Modify RDP Terminal Server Registry Values
Flags reg.exe command lines that modify Terminal Server registry values controlling RDP enablement and behavior.
sigmaWindowshigh2022-02-12PowerShell DirectorySearcher AD Computer Enumeration via System.DirectoryServices.DirectorySearcher
Flags PowerShell DirectorySearcher queries that load directory properties and enumerate results from Active Directory.
sigmaWindowsmedium2022-02-12Windows process creation: flag suspicious program names and PowerShell script indicators
Alerts on suspicious Windows process image names and PowerShell command-line script/tool patterns commonly used in malicious tooling.
sigmaWindowshigh2022-02-11Windows LogMeIn LMIGuardianSvc Execution Associated with Remote Access Tools
Flags Windows process launches identified as LogMeIn LMIGuardianSvc by Description/Product/Company attributes.
sigmaWindowsmedium2022-02-11AnyDesk Executable Execution on Windows
Detects AnyDesk-related process launches on Windows by matching executable names and AnyDesk product metadata.
sigmaWindowsmedium2022-02-11Windows File Creation Indicators for Local SAM Database Exports
Alerts on Windows file creations with filenames indicative of a local SAM export or backup artifact.
sigmaWindowshigh2022-02-11Windows Recent Files Shortcut Points to ISO/IMG/VHD Mount Images
Flags Windows Recent Items entries that reference ISO/IMG/VHD/VHDX mount shortcuts.
sigmaWindowsmedium2022-02-11Windows File Events: AnyDesk user.conf and system.conf Temporary Artefacts
Identifies Windows file writes of AnyDesk user.conf or system.conf in AppData\Roaming.
sigmaWindowsmedium2022-02-11Windows Process Creation: TrolleyExpress.exe Used to Access lsass Memory (PID Parameters)
Alerts on command lines using TrolleyExpress.exe PID parameters consistent with LSASS memory dumping on Windows.
sigmaWindowshigh2022-02-10Windows LSASS memory access from TrolleyExpress/ProcessDump/dump64 processes
Alerts on Windows processes attempting to access lsass.exe from TrolleyExpress.exe, ProcessDump.exe, or dump64.exe with dump-like access rights.
sigmaWindowshigh2022-02-10Windows LSASS Memory Access Triggered by Source Image Containing 'dump' Keyword
Alerts when a process named with 'dump' requests specific access rights to lsass.exe on Windows.
sigmaWindowshigh2022-02-10Windows Script Interpreter Execution From Suspicious Folders via Command-Line Flags
Flags-and-location-based detection of cscript/wscript/mshta-style script execution launched from TEMP/Public/user directories.
sigmaWindowshigh2022-02-08Windows Process Command Line Network Recon via nslookup LDAP SRV Query
Identifies Windows command lines running nslookup with an LDAP SRV domain controller discovery query string.
sigmaWindowshigh2022-02-07