Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: NirCmd runasSystem CommandLine Usage
Alerts on NirCmd being used to run commands as LocalSystem based on the process command line.
sigmaWindowshigh2022-01-24Windows Process Creation: NirCmd Command Execution
Alerts when NirCmd.exe is launched with command-execution-oriented parameters in the process command line.
sigmaWindowsmedium2022-01-24Windows InstallUtil Execution Suspiciously Omitting /logfile Output
Alert when InstallUtil.exe runs from .NET Framework with logging parameters indicating output suppression.
sigmaWindowsmedium2022-01-23Windows PowerShell Scripts Testing Uncommon Port Connectivity via Test-NetConnection
Detects PowerShell scripts using Test-NetConnection to reach a target on non-443/80 ports.
sigmaWindowsmedium2022-01-23Windows PowerShell: Suspicious SslStream Client Certificate Validation in Script Block
Flags PowerShell scripts referencing SslStream and client-side certificate validation during SSL client authentication.
sigmaWindowslow2022-01-23Windows PowerShell: WebRequest User-Agent Modification in ScriptBlockText
Detects PowerShell scripts that make web requests and set a custom -UserAgent value.
sigmaWindowsmedium2022-01-23Windows Office Macro File Creation Triggered by Script/LOLBin Parent Process
Alerts when macro-enabled Office files are created by common Windows script execution processes.
sigmaWindowshigh2022-01-23Windows Office Macro File Creation from Browser or Email Client
Flags Windows creation of macro-enabled Office files (.docm/.xlsm/.pptm) initiated by common browsers or email clients.
sigmaWindowslow2022-01-23Windows Office Macro File Creation via Office Applications
Alerts on creation of macro-enabled Office documents/templates by Office apps on Windows, excluding Office temporary files.
sigmaWindowslow2022-01-23Windows Registry: Internet Settings Zone and Cache-related Key Modifications
Flags registry writes to Windows Internet Settings-related keys that can be abused to alter zone trust or store persistence data.
sigmaWindowslow2022-01-22Windows Registry Set to Hide File Extensions via Explorer Advanced Keys
Flags registry changes under Explorer Advanced that hide file extensions by setting specific DWORD values.
sigmaWindowsmedium2022-01-22Windows Registry: IE ZoneMap Domain Zone Change via ZoneMap\Domains
Flags Windows registry changes to IE ZoneMap domain entries that alter security zone assignments for targeted domains.
sigmaWindowsmedium2022-01-22Radmin Viewer Utility Execution on Windows (Process Creation)
Alerts when Radmin Viewer (Radmin.exe) is launched, based on process metadata in Windows process creation logs.
sigmaWindowsmedium2022-01-22Windows Network Connection Initiated by IMEWDBLD.EXE
Alerts when IMEWDBLD.EXE initiates a network connection on Windows.
sigmaWindowshigh2022-01-22Windows: Suspicious colorcpl.exe file creation/copy to System32 spool drivers color
Alerts on colorcpl.exe creating files in C:\Windows\System32\spool\drivers\color\ with suspicious target filenames.
sigmaWindowshigh2022-01-21Windows Kerberoasting Initial Query: Successful 4769 RC4 Service Requests with Filters
Collects successful Windows 4769 RC4 service-ticket requests while excluding krbtgt and computer/service account patterns for kerberoasting triage.
sigmaWindowsmedium2022-01-21Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Detects AdvancedRun execution where /RunAs is set to specific high-privilege IDs in the process command line.
sigmaWindowshigh2022-01-20Windows PUA AdvancedRun.exe Execution
Detects AdvancedRun.exe executions on Windows with /Run and /RunAs style command-line parameters.
sigmaWindowsmedium2022-01-20Windows Code Integrity: Unmet Signing Level Requirements When Loading a File (Event ID 3033/3034)
Alerts on Code Integrity file-load attempts failing signing level requirements, based on Event ID 3033/3034 in Windows Code Integrity logs.
sigmaWindowslow2022-01-20Windows PowerShell XML Document Load Used for Execution
Flags PowerShell script blocks that use XML document loading combined with expression/command execution keywords.
sigmaWindowsmedium2022-01-19