Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows RMM Tool MeshAgent Execution with Renamed MeshServiceName
Identifies renamed MeshAgent executions on Windows by matching --meshServiceName with OriginalFileName containing meshagent.
sigmaWindowshigh2025-05-19Windows MeshAgent Remote Access Tool Command Line Execution Indicators
Flags Windows processes invoking MeshAgent with --meshServiceName, indicating potential remote access tool execution.
sigmaWindowsmedium2025-05-19Windows Impacket-Pattern File Creation: sessionresume_[a-zA-Z]{8} Indicator
Flags Windows file creations of filenames matching Impacket sessionresume pattern ('sessionresume_<8 letters>').
sigmaWindowshigh2025-05-19Windows WER BugCheck Crash Dump Reporting via Event ID 1001
Flags Windows WER SystemErrorReporting Event ID 1001 entries indicating a crash with bugcheck and dump/report details.
sigmaWindowsmedium2025-05-12Suspicious Inline JavaScript Execution by Node.js (node.exe) on Windows
Flags Windows command lines where node.exe is used with JavaScript execution indicators and module keywords consistent with malicious activity.
sigmaWindowsmedium2025-04-21Windows Process Execution of JavaScript via Node.exe
Alerts when node.exe starts a process with a .js argument on Windows, which may indicate suspicious script execution.
sigmaWindowslow2025-04-21Windows Registry: MiniNt Key Added to Disable Security Event Logging on Reboot
Flags registry set activity that adds the MiniNt key, which stops Windows Event Log from writing events after a reboot.
sigmaWindowshigh2025-04-09Windows Process Creation: Disabling Security Logging via MiniNt Registry Key Set
Flags reg.exe or PowerShell commands that create/modify the MiniNt registry key to impair Windows event logging.
sigmaWindowshigh2025-04-09Windows PowerShell History File Access Attempt via ConsoleHost_history.txt
Alerts on Windows process executions whose command line references PowerShell console history files or HistorySavePath.
sigmaWindowsmedium2025-04-03Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.
sigmaWindowshigh2025-03-25Windows Process Creation: Suspicious LNK Command-Line Whitespace Padding Beyond UI Limit
Alerts when explorer.exe launches a .lnk and the command line contains suspicious whitespace padding used to hide extended arguments.
sigmaWindowshigh2025-03-19Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Flags PowerShell script blocks that query AD computer delegation-related properties using Get-ADComputer-style discovery.
sigmaWindowsmedium2025-03-05Windows Process Creation: AdFind.exe Execution for Active Directory Recon
Alerts on Windows execution of AdFind.exe based on image/name and known imphash values indicative of AD reconnaissance.
sigmaWindowsmedium2025-02-26Windows: Notepad Password File Discovery via Process Creation
Flags explorer-launched Notepad opening files named like password*.{txt,csv,doc,xls} that may contain credentials.
sigmaWindowslow2025-02-21Suspicious autorun registry modification via WMI wmic spawning reg.exe on Windows
Flags WMIC-driven reg.exe commands that add Run key autorun entries, especially when pointing to suspicious temp/user locations.
sigmaWindowshigh2025-02-17Windows File Events: Suspicious WDAC Policy File Creation by Non-Excluded Processes
Alerts on WDAC-related policy files created under CodeIntegrity, excluding known deployment tools and scripts.
sigmaWindowsmedium2025-02-07Windows Scheduled Task Creation Using System Process Names
Flags schtasks.exe /create commands whose arguments reference common Windows system process names.
sigmaWindowshigh2025-02-05Windows Scheduled Task Creation via schtasks.exe with curl and PowerShell Command Line Indicators
Alerts on schtasks.exe task creation commands that simultaneously include curl download indicators and PowerShell execution.
sigmaWindowsmedium2025-02-05Windows Process Creation: NimScan.exe Execution via Known File Hashes
Alerts on Windows execution of NimScan.exe when process image and known IMPHASH values match.
sigmaWindowsmedium2025-02-05Windows MMC Executes Files with RLO-Reversed Extensions in Process Command Line
Alerts when mmc.exe runs with command lines containing RLO-style reversed filename patterns ending in .msc.
sigmaWindowshigh2025-02-05