Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
PowerShell MsXml2.XmlHttp COM Object Instantiation
Alerts on PowerShell creating an MsXml2.XmlHttp COM object through New-Object -ComObject.
sigmaWindowsmedium2022-01-19Windows Registry: Disable Administrative Share Creation via LanmanServer Parameters
Flags registry writes that disable Windows administrative share auto-creation under LanmanServer parameters.
sigmaWindowsmedium2022-01-16Windows msiexec.exe Quiet MSI Installation with Installer Arguments
Flags msiexec.exe launched with -q plus MSI installer switches, indicating quiet installation behavior in Windows process creation logs.
sigmaWindowsmedium2022-01-16Windows: Suspicious msiexec.exe Command-Line Writes Install Logs with /Y
Alerts on suspicious msiexec.exe executions using the /Y argument that are not consistent with common installer locations.
sigmaWindowsmedium2022-01-16Windows DISM Online Disable-Feature via DismHost.exe or Dism.exe
Flags Windows DISM/DismHost executions using /Online and /Disable-Feature, a common defense-impairment technique.
sigmaWindowsmedium2022-01-16PowerShell ScriptBlock Logging: Set-MpPreference disables Windows Defender scanning or allows threats
Alert on PowerShell Set-MpPreference usage that disables Defender scanning/monitoring or sets threat default actions to Allow.
sigmaWindowshigh2022-01-16Windows: Deletion of TeamViewer log files
Alerts on deletion of TeamViewer *.log files on Windows, excluding deletions performed by svchost.exe.
sigmaWindowslow2022-01-16Windows rmdir Directory Removal via cmd.exe Execution
Monitors cmd.exe process creation where rmdir is used with /s and/or /q to delete directories and reduce forensic artifacts.
sigmaWindowslow2022-01-15Windows del/erase Command-Line File Deletion via cmd.exe
Flags cmd.exe executions running del/erase for file removal, including common flags like /f, /s, and /q.
sigmaWindowslow2022-01-15Windows PowerShell: Start-Process with -PassThru and -FilePath
Alerts on PowerShell Start-Process calls that include -PassThru and -FilePath, based on ScriptBlockText matches.
sigmaWindowsmedium2022-01-15Windows rundll32 Execution With Uncommon DLL/CPL/INF Extension in Command Line
Alerts on Windows rundll32 executions whose command lines lack common .cpl/.dll/.inf endings, indicating potential unusual invocation.
sigmaWindowsmedium2022-01-13Windows Sysmon Configuration Change (Event ID 16)
Alerts on Sysmon configuration changes via Sysmon Event ID 16 on Windows.
sigmaWindowsmedium2022-01-12Windows: Process creation event for Sysmon uninstall using Sysmon -u
Flags attempts to uninstall Sysmon on Windows by running Sysmon with the -u flag.
sigmaWindowshigh2022-01-12PowerShell Script Creates Volume Shadow Copy via Win32_ShadowCopy
Alerts when PowerShell script blocks invoke Win32_ShadowCopy.Create to create a ClientAccessible shadow copy.
sigmaWindowshigh2022-01-12Windows ProcDump renamed, copied or moved for stealth evasion
Alerts on ProcDump commands that copy/move or rename dump outputs, including LSASS dump filename patterns.
sigmaWindowshigh2022-01-11Windows regsvr32 Downloads Remote DLLs via HTTP/HTTPS IP in /i Parameter
Alerts when regsvr32 is invoked with an /i: HTTP/HTTPS IP pattern to fetch remote DLLs.
sigmaWindowshigh2022-01-11Windows Process Execution: Microsoft.NodejsTools.PressAnyKey.exe Child Spawns
Flags child processes started by Microsoft.NodejsTools.PressAnyKey.exe, which may be abused to run arbitrary binaries.
sigmaWindowsmedium2022-01-11Windows mpiexec.exe LOLBin: Flag combination with -n/n 1 for potential arbitrary execution
Alerts on Windows executions of mpiexec.exe with /n 1 or -n 1, correlated to a specific imphash, indicating LOLBin-style behavior.
sigmaWindowshigh2022-01-11Windows: Detect devinit.exe MSI download flag combo (-t msi-install, -i http)
Alerts on devinit.exe command lines that combine MSI install with an HTTP download source.
sigmaWindowsmedium2022-01-11Windows Browser Process Spawned with Inline URL Pointing to Suspicious File Extension
Flags Windows browser processes launched with an inline HTTP URL pointing to files with suspicious extensions.
sigmaWindowsmedium2022-01-11