Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: Executable Image Missing Absolute Path (Possible Process Ghosting)
Flags Windows process creation where the executable Image lacks an absolute path, potentially indicating process ghosting.
sigmaWindowshigh2021-12-09Windows Process Creation: Suspicious Network Configuration and Discovery Commands
Alerts on Windows command-line usage of network configuration and discovery tools (ipconfig, netsh, arp, nbtstat, net config, route print).
sigmaWindowslow2021-12-07Windows netsh.exe Firewall Configuration Discovery (show firewall rule/state/name=all)
Flags netsh.exe commands used to enumerate Windows firewall rules and states via “show firewall … name=all”.
sigmaWindowslow2021-12-07Windows PowerShell Process Creation with DInjector Cradle Flags (/am51 and /password)
Identifies Dinject PowerShell cradle usage by matching command-line flags '/am51' and '/password' in Windows process creation.
sigmaWindowscritical2021-12-07Windows: Suspicious PowerShell Interactive History Files Created as SYSTEM
Alerts on creation of PowerShell interactive history/profile files under SYSTEM, signaling privileged PowerShell activity.
sigmaWindowshigh2021-12-07Windows: User Added to Local Remote Desktop Users Group via Net or PowerShell
Detects Windows command-line activity that adds a user to the local Remote Desktop Users group using net localgroup or Add-LocalGroupMember.
sigmaWindowshigh2021-12-06Windows: Network connections initiated to api.mega.co.nz or mega.nz
Identifies initiated Windows outbound connections to api.mega.co.nz/mega.nz for potential file-transfer staging.
sigmaWindowslow2021-12-06Windows: Remote Network Share Writes to desktop.ini
Flags remote network-shared desktop.ini being written to with high-impact permissions in Windows Security logs.
sigmaWindowsmedium2021-12-06Windows System Logs: Windows Update Client errors (connection, install, uninstall, revert, commit)
Alerts on Windows Update Client errors in System logs, including connection, install, uninstall, revert, and commit failures.
sigmaWindowsinformational2021-12-04Windows Process Command Line Containing Whoami as First Parameter
Flags Windows process creations with command lines containing '.exe whoami' to surface potential discovery behavior.
sigmaWindowshigh2021-11-29Windows Regsvr32.exe Executed with Suspicious File Extension Masquerading as DLL
Alerts when REGSVR32.exe runs with a command-line argument ending in a suspicious masquerade file extension.
sigmaWindowshigh2021-11-29Windows File Writes from NPPSpy Hacktool: NPPSpy.txt and NPPSpy.dll
Alerts on Windows file events writing NPPSpy.txt or NPPSpy.dll, consistent with credential dumping by the NPPSpy hacktool.
sigmaWindowshigh2021-11-29Windows LSASS Process Clone Execution Observed
Alerts on process creation where LSASS creates a new LSASS clone, which may indicate credential dumping activity.
sigmaWindowscritical2021-11-27Windows extrac32.exe CAB extraction via Alternate Data Stream execution
Flags Windows executions of extrac32.exe that target a .cab and include an alternate data stream path indicator.
sigmaWindowsmedium2021-11-26Windows Diantz.exe Command-Line ADS CAB Creation
Flags Diantz commands that create or reference a .cab using an Alternate Data Stream (ADS) pattern on Windows.
sigmaWindowsmedium2021-11-26Windows Process Creation: Dump64.EXE Renamed into Visual Studio Folder
Alerts on Visual Studio–staged dump64.exe masquerading, potentially indicating an attempt to bypass Windows Defender AV.
sigmaWindowshigh2021-11-26Windows ConfigSecurityPolicy.EXE Used for HTTP/FTP Arbitrary File Transfers
Alert when ConfigSecurityPolicy.exe runs with ftp/http/https URLs in the command line, indicating potential file transfer abuse.
sigmaWindowsmedium2021-11-26Windows PowerShell Clears Console History via Clear-History
Flags PowerShell attempts to clear or delete console/PSReadline command history to hinder command forensics.
sigmaWindowshigh2021-11-25Windows: Rundll32 Loading shell32.dll via Control_RunDLL from User/Temp Paths
Alerts on rundll32.exe loading shell32.dll with Control_RunDLL from AppData/Temp/user paths.
sigmaWindowshigh2021-11-24Windows CertReq -Post Download Attempt via HTTP
Flags certreq.exe executions using -Post -config and HTTP content retrieval indicators.
sigmaWindowshigh2021-11-24