Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Exchange Management: Certificate CSR exported to webserver or .aspx-named path
Flags Exchange CSR export commands that write request files to C$ and web-root paths or use an .aspx filename.
sigmaWindowscritical2021-08-23PowerShell Write-Hijack HackTool Creates .bat for DLL Hijack Execution (Windows)
Flags PowerShell creating .bat files consistent with PowerUp Write-Hijack DLL abuse on Windows.
sigmaWindowshigh2021-08-21Windows: Detect reg.exe Changing Screen Saver Registry Settings for .scr Payloads
Flags reg.exe command lines that modify HKCU desktop screensaver settings and configure a .scr screen saver payload.
sigmaWindowsmedium2021-08-19PowerShell WMI Event Subscription Persistence via New-CimInstance
Finds PowerShell creating WMI __EventFilter and CommandLineEventConsumer objects for event-triggered persistence.
sigmaWindowsmedium2021-08-19Windows PowerShell: Add-Content to $profile for Potential Persistence
Detects PowerShell Add-Content writing to $profile, especially when paired with common command-loading or execution payloads.
sigmaWindowsmedium2021-08-18Windows Procdump Process Execution
Alerts on execution of Sysinternals Procdump (32/64 variants) based on process creation image path.
sigmaWindowsmedium2021-08-16Windows whoami.exe Execution from Suspicious Parent Processes
Alerts on whoami.exe runs where the parent process is not a typical shell or monitoring agent.
sigmaWindowsmedium2021-08-12Windows whoami.exe Renamed Execution via Mismatched OriginalFileName
Alerts when a renamed process still reports OriginalFileName as whoami.exe on Windows.
sigmaWindowscritical2021-08-12Windows Maldoc Process Injection via winword.exe CallTrace from LittleCorporal
Flags winword.exe process injection where the call trace matches LittleCorporal-generated Maldoc activity on Windows.
sigmaWindowshigh2021-08-09PowerShell ShellIntel Commandlet Abuse via ScriptBlock Logging
Flags PowerShell script blocks that reference known ShellIntel commandlets tied to exploitation activity.
sigmaWindowshigh2021-08-09Microsoft Exchange: Mailbox export to UNC path or .aspx filename with possible role assignment
Flags Exchange mailbox export commands targeting UNC paths with .aspx or granting the Mailbox Import Export role.
sigmaWindowscritical2021-08-09Windows Exchange Management: Set-OabVirtualDirectory after ProxyLogon exploitation
Flags Exchange management command lines invoking Set-OabVirtualDirectory with suspicious external URL/script injection patterns.
sigmaWindowscritical2021-08-09Windows AnyDesk Silent Installation via Command-Line Flags
Identifies AnyDesk being silently installed on Windows using --install, --start-with-win, and --silent command-line flags.
sigmaWindowshigh2021-08-06Windows esentutl Usage with /p Flag for Credential Access
Flags Windows executions of esentutl when used with the /p parameter to access credentials-related files.
sigmaWindowsmedium2021-08-06Windows Registry: Tamper Protection Disabled in Microsoft Defender Features
Flags registry changes that set Microsoft Defender Tamper Protection to disabled (DWORD 0x0), excluding expected MsMpEng update activity.
sigmaWindowsmedium2021-08-04Windows Registry: Disabling Windows Defender PUA Protection via PUAProtection DWORD
Flags registry changes that set Windows Defender PUAProtection DWORD to 0x00000000 to disable PUA protection.
sigmaWindowshigh2021-08-04Windows Registry: Disable Windows Defender Exploit Guard Network Protection via Policy Override
Alerts on registry policy changes that override Exploit Guard Network Protection settings for Windows Defender.
sigmaWindowsmedium2021-08-04Windows process access matching Cobalt Strike BOF injection call trace
Flags suspicious Windows process access consistent with CobaltStrike BOF injection using ntdll/KERNELBASE call traces and high GrantedAccess.
sigmaWindowshigh2021-08-04PowerShell timestomping via file timestamp property and setter usage (Windows)
Identifies PowerShell timestomping attempts by matching script text that sets file creation, access, and write timestamps.
sigmaWindowsmedium2021-08-03PowerShell Virtualization Environment Discovery via WMI in ScriptBlockLogging (Windows)
Identifies PowerShell WMI queries for Win32 computer system and ACPI thermal data used to check virtualization environments.
sigmaWindowsmedium2021-08-03