Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows bash.exe Launched with -c for Indirect Inline Command Execution
Alerts on Windows processes starting bash.exe with -c, indicating inline command execution.
sigmaWindowsmedium2021-11-24Windows: aspnet_compiler.exe Execution Detection
Detects execution of aspnet_compiler.exe from Windows .NET Framework directories, which can be abused to compile and run C#.
sigmaWindowsmedium2021-11-24Windows DNS Queries Triggered by DesktopAppInstaller AppInstaller.EXE
Identifies DNS lookups performed by Windows AppInstaller.EXE when initiating ms-appinstaller package installation from a URL.
sigmaWindowsmedium2021-11-24Windows PsExec/PAExec Command-Line Flags Escalating to LOCAL SYSTEM
Flags in PsExec/PAExec command lines requesting LOCAL SYSTEM execution are matched via process creation command-line telemetry.
sigmaWindowshigh2021-11-23Windows process access to LSASS.exe with suspicious GrantedAccess flags
Alerts on process access attempts to lsass.exe with GrantedAccess rights commonly linked to credential theft behavior.
sigmaWindowsmedium2021-11-22Windows Shell/Scripting Tool File Write to Suspicious Directories
Alert on file writes by common Windows shells/scripting tools to C:\PerfLogs, C:\Users\Public, or C:\Windows\Temp.
sigmaWindowshigh2021-11-20Windows Registry New File Association via exefile Handler (Classes\*.exefile)
Alerts on Windows registry changes creating a new file association that points to the exefile handler.
sigmaWindowshigh2021-11-19Windows WinRAR or RAR Utility Execution from Non-Default Installation Paths
Alerts on WinRAR/RAR process execution when launched from folders outside standard WinRAR installation paths.
sigmaWindowsmedium2021-11-17Windows ADCS Template Enrollment Supplies Subject and Risky EKU (Event ID 4898/4899)
Flags ADCS template load/update events (4898/4899) when risky EKU OIDs and enrollee-supplied subject are present.
sigmaWindowshigh2021-11-17Windows AD CS Certificate Template Updated/Created Enrollee Supplies Subject Flag
Alerts when AD CS certificate templates are created or updated with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT.
sigmaWindowslow2021-11-17Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Alerts on scheduled task storage writes under System32\Tasks originating from suspicious process locations.
sigmaWindowshigh2021-11-16Windows: reg.exe Adds BitLocker Policy Registry Values
Flags reg.exe registry additions targeting BitLocker policy keys associated with configuration changes.
sigmaWindowshigh2021-11-15Windows LSASS Memory Dump File Creation
Alerts on Windows file creation of LSASS memory dump artifacts identified by high-confidence filename patterns.
sigmaWindowshigh2021-11-15Windows Office Apps Initiate Outbound Network Connections to Non-Private IPs
Alerts when Office app processes initiate outbound TCP/HTTP(S)/mail connections to non-private IPs, excluding common private and known provider ranges.
sigmaWindowsmedium2021-11-10Suspicious DNS Query Patterns for Cobalt Strike Beacons on Windows (Sysmon)
Alerts on Windows Sysmon DNS queries with QueryName patterns consistent with Cobalt Strike DNS beaconing.
sigmaWindowscritical2021-11-09Windows HackTool Activity: Mimikatz Kerberos Ticket and MemSSP File Creation
Alerts on Windows file creation events for Mimikatz-related .kirbi and mimilsa.log files.
sigmaWindowscritical2021-11-08Windows ZipExec-Style Suspicious PowerShell/Command Execution with Password-Protected ZIP
Flags Windows processes running ZipFolder zip commands with password and .zip filename parameters, optionally including deletion.
sigmaWindowsmedium2021-11-07Windows Process Creation: cscript/wscript Register-App.vbs COM+ Registration
Alert on cscript/wscript running “.vbs -register” to register COM+ components, potentially leveraging register_app.vbs.
sigmaWindowsmedium2021-11-05Windows: Cmdl32.EXE Arbitrary File Download Indicator via /vpn and /lan Flags
Flags cmdl32.exe executions using /vpn and /lan that may indicate arbitrary file retrieval behavior.
sigmaWindowsmedium2021-11-03Windows Process Creation: PowerShell ExecutionPolicy Set to Bypass/Unrestricted
Alerts on PowerShell started with -ExecutionPolicy set to Bypass/Unrestricted, indicating a potentially insecure script execution posture.
sigmaWindowsmedium2021-11-01