Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: Pypykatz Credential Dumping via Registry Parsing
Alerts when pypykatz is run with "live" and "registry" parameters to extract credential data from local SAM-related artifacts.
sigmaWindowshigh2022-01-05Windows WinRAR Compression of .dmp/.dump Files via Command Line
Flags WinRAR executions on Windows whose command lines reference .dmp/.dump/.hdmp extensions.
sigmaWindowsmedium2022-01-04Windows: Uncommon format.com File System Load via /fs parameter
Alerts on format.com executions with atypical /fs: parameters, which may indicate defense-evasion use of Windows utilities.
sigmaWindowshigh2022-01-04Windows Process Creation: createdump.exe Dumping Memory with Full and Name Flags
Flags and .dmp output usage indicate createdump.exe dumping process memory on Windows.
sigmaWindowshigh2022-01-04Windows Process Creation: Headless Chromium Download via dump-dom
Flags headless Chromium browser executions using dump-dom and an http URL on Windows, indicative of stealthy remote content retrieval.
sigmaWindowshigh2022-01-04Windows Process Creation: cscript/wscript Running gatherNetworkInfo.vbs
Alerts on cscript/wscript processes running gatherNetworkInfo.vbs, indicating potential host/network reconnaissance.
sigmaWindowsmedium2022-01-03Suspicious PowerShell Execution with Base64 Encoded Command (Windows)
Alerts on PowerShell launched with Base64-encoded command-line parameters, excluding likely Guest Configuration noise.
sigmaWindowsmedium2022-01-02Windows PowerShell Starts Process Using Batch (.cmd/.bat) Scripts
Flags PowerShell Start-Process activity that references .bat/.cmd files, indicating batch script execution attempts.
sigmaWindowsmedium2022-01-02Windows Backup File Deletion Triggered by CLI or Script Hosts
Alerts when cmd.exe, PowerShell, wt.exe, rundll32.exe, or regsvr32.exe delete files with backup-oriented filename extensions.
sigmaWindowsmedium2022-01-02Windows Registry: RDP PortNumber changed from default 3389
Alerts on Windows registry updates to the RDP-Tcp PortNumber when it changes away from default 3389.
sigmaWindowshigh2022-01-01Windows WMIC Process Flag Execution Indicating Process Reconnaissance
Alerts on wm ic.exe executions using the 'process' flag, consistent with attempting to enumerate running processes.
sigmaWindowsmedium2022-01-01Windows Process Creation: Suspicious systeminfo.exe Execution
Alerts on execution of systeminfo.exe (or sysinfo.exe) via Windows process creation logs for system discovery.
sigmaWindowslow2022-01-01Windows Suspicious Shutdown or Reboot via shutdown.exe Command-Line
Flags shutdown.exe executions that include reboot (/r) or shutdown (/s) switches in the command line.
sigmaWindowsmedium2022-01-01Windows Process Creation: Suspicious reg.exe Query for MachineGuid
Detects reg.exe queries for MachineGuid under SOFTWARE\Microsoft\Cryptography via process creation logs.
sigmaWindowslow2022-01-01Windows adidnsdump Execution via python.exe
Detects python.exe running adidnsdump, a DNS-record enumeration tool used for internal AD recon.
sigmaWindowslow2022-01-01Windows: Suspicious Process Execution of hostname.exe
Flags execution of hostname.exe from process creation events on Windows for discovery activity.
sigmaWindowslow2022-01-01Windows Winlogon Notify Registry Key DLL Persistence (logon)
Alerts on DLL-specified Winlogon Notify logon entries created via registry set events.
sigmaWindowshigh2021-12-30Windows Registry Modification of Application Shim Database (InstalledSDB/Custom) for Persistence
Alerts on registry changes to Windows AppCompatFlags InstalledSDB/Custom that may enable shim-based persistence.
sigmaWindowsmedium2021-12-30Windows Registry: Add Print Port Monitor DLL Persistence
Flags registry updates to Print Port Monitors that reference .dll components for potential startup persistence on Windows.
sigmaWindowsmedium2021-12-30Windows Reg.exe Modifies Service ImagePath in HKLM\SYSTEM\CurrentControlSet\Services
Alerts on reg.exe commands that target HKLM\SYSTEM\CurrentControlSet\Services\ImagePath modifications.
sigmaWindowsmedium2021-12-30