Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Flags conhost.exe spawning command/scripting utilities like PowerShell, MSHTA, or regsvr32.exe.
sigmaWindowshigh2025-02-05Windows MMC Loads Script Engine DLLs (vbscript.dll, jscript.dll, jscript9.dll)
Alerts when mmc.exe loads vbscript/jscript script engine DLLs, which can indicate script execution in a trusted process.
sigmaWindowsmedium2025-02-05Windows file creation of executable/script files in \Users\Public
Alerts on Windows file creation in \Users\Public\ with potentially malicious script/binary extensions.
sigmaWindowshigh2025-01-23Windows: Clfs.sys Loaded from Suspicious Process Image Paths
Alerts when clfs.sys is loaded by a process running from user/temp/perflogs-style suspicious paths on Windows.
sigmaWindowsmedium2025-01-20Windows Registry EventLog ChannelAccess SDDL Tampering Detection
Detects registry changes to Windows Event Log ChannelAccess SDDL, which can limit event log visibility or control.
sigmaWindowshigh2025-01-16Windows Process Creation: Microsoft QuickAssist.exe Execution
Alerts on execution of QuickAssist.exe by matching the process image ending with \QuickAssist.exe.
sigmaWindowslow2024-12-19Windows DNS Queries Initiated by QuickAssist.exe to remoteassistance.support.services.microsoft.com
Alerts when QuickAssist.exe performs DNS lookups for the Microsoft Quick Assist remote session endpoint.
sigmaWindowslow2024-12-19Windows Setup16.EXE Execution Triggered by Custom .LST File
Flags Windows Setup16.EXE being invoked with ' -m ' from its system parent process, potentially tied to custom .lst-driven execution.
sigmaWindowsmedium2024-12-01Windows Suspicious ShellExec_RunDLL via SHELL32.DLL Ordinal in Parent Command Line
Alert on Windows process starts where parent command line invokes SHELL32.DLL ShellExec_RunDLL using a matched ordinal and spawns suspicious binaries.
sigmaWindowshigh2024-12-01Windows File Event: Detect RTLO Filename Extension Spoofing
Flags Windows filenames containing U+202E plus reversed extension strings that indicate potential extension spoofing.
sigmaWindowshigh2024-11-17Windows Registry RunMRU PowerShell or WMIC Execution Command Indicators
Alerts on RunMRU registry entries showing PowerShell (encoding/invocation) or WMIC shadowcopy/process call usage.
sigmaWindowshigh2024-11-01Windows IIS module removal event (IIS-configuration EventID 29)
Detects removal of an IIS module from Windows IIS configuration events (Event ID 29).
sigmaWindowslow2024-10-06Windows IIS Configuration: New Module Added to /system.webServer/modules
Flags IIS configuration events where a new module is added under /system.webServer/modules.
sigmaWindowsmedium2024-10-06IIS HTTP Logging Disabled via dontLog Configuration Change (Windows)
Alerts on IIS configuration updates that disable HTTP logging by setting dontLog to true for successful requests.
sigmaWindowshigh2024-10-06Windows IIS Configuration: Disable ETW Logging/Processing via logTargetW3C Change
Identifies IIS configuration edits that remove/disable ETW logging or processing for W3C log targeting.
sigmaWindowsmedium2024-10-06Windows MeshAgent remote command execution via cmd.exe or PowerShell child processes
Flags cmd.exe or PowerShell spawned by meshagent.exe on Windows, indicating potential remote command execution.
sigmaWindowsmedium2024-09-22Windows Process Initiated Connections to .btunnel.co.in Domains
Flags initiated outbound connections to .btunnel.co.in domains from a Windows host.
sigmaWindowsmedium2024-09-13Windows: GPO Modification Adds Startup/Logon Script References
Flags GPO changes that add startup/logon scripts (SYSVOL scripts.ini) for user or computer targets using Windows directory/audit events.
sigmaWindowsmedium2024-09-06Windows Security: Group Policy Object modification adds privileges to user accounts
Alerts on Windows GPO attribute changes that correspond to adding privileges or making users local admins.
sigmaWindowsmedium2024-09-04Windows DISM Enables PowerShell Web Access Feature via Command Line
Flags DISM executions that enable the WindowsPowerShellWebAccess feature using /online and /enable-feature parameters.
sigmaWindowshigh2024-09-03