Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: cmd.exe Launching with PowerShell in .lnk Link Command
Alerts when explorer launches cmd.exe with command lines containing both PowerShell and a .lnk reference.
sigmaWindowsmedium2022-02-06Windows PowerShell: DSInternals Get-ADReplAccount Enumeration
Alerts on PowerShell execution of Get-ADReplAccount with -All and -Server parameters for AD replication account enumeration.
sigmaWindowsmedium2022-02-06Windows Registry ServiceDll Hijack via Service Parameters\ServiceDll
Alerts on ServiceDll value changes for Windows services in the registry, indicating potential DLL load persistence.
sigmaWindowsmedium2022-02-04Windows NTLM brute force targeting workstation/device names
Alerts on NTLM EventID 8004 when WorkstationName equals common spoofed client names used in brute force attempts.
sigmaWindowsmedium2022-02-02Windows PowerShell: Suspicious Unblock-File to Remove Zone.Identifier
Flags PowerShell use of Unblock-File (-Path) that can remove Zone.Identifier downloaded-file metadata.
sigmaWindowsmedium2022-02-01PowerShell Mount-DiskImage with -ImagePath to Access Disk Images
Alerts on PowerShell script blocks calling Mount-DiskImage with -ImagePath, indicative of disk-image-based payload staging.
sigmaWindowslow2022-02-01Windows PowerShell: Suspicious Invoke-Item After Mount-DiskImage
Flags PowerShell that mounts an image, derives a drive letter, then runs content via invoke-item from that mount.
sigmaWindowsmedium2022-02-01Windows Suspicious takeown.exe Recursive Ownership Change
Alerts when takeown.exe is run with recursive and file/folder targeting, indicating potential defense impairment via ownership changes.
sigmaWindowsmedium2022-01-30Windows PowerShell ScriptBlock Accessing Browser 'Login Data' Files
Flags PowerShell Copy-Item operations targeting browser Login Data credential database paths on Windows.
sigmaWindowsmedium2022-01-30Windows File Writes of TeamViewer Session Logs
Flags Windows file creation events for TeamViewer session log artifacts like vprint.db and TVNetwork.log.
sigmaWindowsmedium2022-01-30Windows DNS Queries for TeamViewer Domains Triggered by Non-TeamViewer Image
Alerts when TeamViewer domains are resolved via DNS by a process whose image name does not include "TeamViewer".
sigmaWindowsmedium2022-01-30Windows: Application Uninstall via WMIC.exe (WMIC call uninstall)
Flags WMIC.exe commands that include "call" and "uninstall," indicating potential application removal on Windows.
sigmaWindowsmedium2022-01-28Windows: whoami.exe Executed by Privileged Accounts
Flags execution of whoami.exe from privileged-like accounts using Windows process creation events.
sigmaWindowshigh2022-01-28Windows: Detect XORDump Utility Launch With LSASS Dump and Debug Module Switches
Alerts on xordump.exe spawning with LSASS-targeting and dump-module switches indicative of credential theft.
sigmaWindowshigh2022-01-28Windows File Creation of TeamViewer_Desktop.exe During Install
Alerts on Windows when TeamViewer_Desktop.exe is created, indicating potential installation or dropped remote-access binaries.
sigmaWindowsmedium2022-01-28Windows Installer Application Removed via MsiInstaller Events
Alerts on Windows Installer events indicating an application was removed via MsiInstaller.
sigmaWindowslow2022-01-28Windows Process Hollowing Suspected via Replaced In-Memory Image
Alerts on Windows events where a process image is replaced in memory, suggesting possible process hollowing.
sigmaWindowsmedium2022-01-25Windows LOLBIN Execution From Abnormal Drive (calc, certutil, mshta, regsvr32, rundll32)
Flags Windows LOLBIN execution when process CurrentDirectory is not empty/null and contains C:\, indicating unusual launch context.
sigmaWindowsmedium2022-01-25Windows: RunXCmd Command-Line Execution with System or TrustedInstaller Accounts
Flags RunXCmd usage on Windows when invoked to execute commands as System or TrustedInstaller.
sigmaWindowshigh2022-01-24Windows Process Execution: NSudo (NSudo.exe/NSudoLC/NSudoLG)
Alerts on NSudo execution on Windows with privilege and integrity/elevation command-line parameters.
sigmaWindowshigh2022-01-24