Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: Command-Line Indicators of Crypto Mining
Alerts on Windows processes with command-line arguments matching common crypto miner pool and configuration indicators.
sigmaWindowshigh2021-10-26Windows Process Creation: Suspicious Command-Line Path Traversal Evasion Strings
Flags Windows command-line strings that look like “..\” path traversal evasion attempts, excluding known Google Drive and Citrix launcher patterns.
sigmaWindowsmedium2021-10-26Windows Network Connections to Known Crypto Mining Pools
Flags Windows hosts making outbound connections to known cryptocurrency mining pool domains.
sigmaWindowshigh2021-10-26Windows Browser Process Creating VHD/VHDX Files via Download
Alerts when a Windows browser process creates files containing .vhd, indicating potential VHD/VHDX staging.
sigmaWindowsmedium2021-10-25PowerShell Creating Startup .lnk Shortcut Persistence (Windows File Events)
Detects PowerShell writing .lnk files into the Windows Startup folder, a common persistence mechanism.
sigmaWindowshigh2021-10-24Windows: CertOC.exe certificate utility loading a DLL via -LoadDLL
Flags CertOC.exe launching with -LoadDLL to load a specified DLL on Windows.
sigmaWindowsmedium2021-10-23Windows Process Execution via WorkFolders.exe Launching control.exe
Alerts when WorkFolders.exe spawns a non-standard control.exe instance on Windows.
sigmaWindowshigh2021-10-21Windows process execution via stordiag.exe launching schtasks.exe, systeminfo.exe, or fltmc.exe
Detects stordiag.exe spawning schtasks.exe, systeminfo.exe, or fltmc.exe to support system discovery or config actions on Windows.
sigmaWindowshigh2021-10-21PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)
Flags PowerShell script block text indicating WindowStyle set to Hidden, suggesting concealed execution.
sigmaWindowsmedium2021-10-20PowerShell: Set-ExecutionPolicy to Unrestricted or Bypass
Alerts when PowerShell sets execution policy to Unrestricted or bypass, indicating weakened script execution controls.
sigmaWindowsmedium2021-10-20Windows Registry: Clearing RDP Client Connection History via MRU and Server Keys Deletion
Flags registry deletions that remove Windows RDP client connection history from Terminal Server Client MRU and Servers keys.
sigmaWindowshigh2021-10-19Windows PowerShell: Disable Windows Firewall Profile via Set-NetFirewallProfile
Flags PowerShell commands that disable one or more Windows Firewall profiles via Set-NetFirewallProfile -Enabled $false.
sigmaWindowsmedium2021-10-12Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
sigmaWindowshigh2021-10-08Windows Named Pipe Access to ADFS/WID Database by Uncommon Process
Alert on named pipe creation to the AD FS WID SQL query endpoint when initiated by uncommon processes.
sigmaWindowsmedium2021-10-08Windows: Suspicious Driver Installation via pnputil.exe
Flags pnputil.exe command lines indicating driver install/add actions targeting .inf files on Windows.
sigmaWindowsmedium2021-09-30Windows DataSvcUtil.exe Command-Line Exfiltration Using /in:, /out:, and /uri:
Alerts on DataSvcUtil.exe runs with /in:, /out:, and /uri: parameters that may indicate data exfiltration activity.
sigmaWindowsmedium2021-09-30Windows Prefetch File Deletion via .pf File Removal
Flags deletion of .pf files in \\Windows\\Prefetch, a possible attempt to remove execution artifacts.
sigmaWindowshigh2021-09-29Windows Process Memory Dump Using RdrLeakDiag.exe (/memdmp|fullmemdmp)
Alerts on Windows executions of rdrleakdiag.exe that request full or targeted memory dumps via /memdmp or /fullmemdmp.
sigmaWindowshigh2021-09-24PowerShell Live Memory Dump via Get-StorageDiagnosticInfo with -IncludeLiveDump (Windows)
Identifies PowerShell use of Get-StorageDiagnosticInfo with -IncludeLiveDump to trigger a live memory dump on Windows.
sigmaWindowshigh2021-09-21Windows: Xwizard.exe Execution from Non-Default Directory
Alerts when Xwizard.exe starts from an unexpected Windows path, indicating potential misuse or side-loading.
sigmaWindowshigh2021-09-20