Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Creation: ADCSPwn Command-Line Parameters Indicating ADCS Abuse
Identifies Windows processes with command-line arguments consistent with ADCSPwn targeting ADCS and a specified port.
sigmaWindowshigh2021-07-31Windows Process Creation: Recon Data Export via Command Prompt Redirection
Alerts when recon-related Windows utilities are launched with command-line output redirected to temp locations.
sigmaWindowsmedium2021-07-30Windows: Suspicious Cabinet (CAB) File Expansion via expand.exe from Uncommon Paths
Flags expand.exe ("-F:") extracting cabinets when used from suspicious/uncommon Windows paths.
sigmaWindowsmedium2021-07-30Windows PowerShell Recon via Export-Oriented Commands in Script Block Logging
Detects PowerShell script blocks performing recon queries (services/processes) and writing output to TEMP.
sigmaWindowsmedium2021-07-30PowerShell Keylogging via Get-Keystrokes and Win32 API Calls (GetAsyncKeyState, GetForegroundWindow)
Flags PowerShell script blocks containing Get-Keystrokes with GetAsyncKeyState/GetForegroundWindow for potential keylogging.
sigmaWindowsmedium2021-07-30Windows Named Pipe Creation: Cobalt Strike Malleable Profile PipeName Patterns
Alerts on Sysmon named pipe creation with PipeName patterns commonly used by Cobalt Strike malleable C2.
sigmaWindowshigh2021-07-30Windows Named Pipe Creation Matching Cobalt Strike Malleable C2 Profile Patterns
Alerts on Windows named pipe creation with PipeName patterns consistent with Cobalt Strike Malleable C2 behavior.
sigmaWindowscritical2021-07-30Windows WinDivert Driver Load via Image or Known IMPHASHes
Detects WinDivert-related Windows driver loads using loaded image paths or known IMPHASH values.
sigmaWindowshigh2021-07-30PowerShell SAM Hive Copy via Volume Shadow Copy Paths on Windows
Flags PowerShell commands that copy the SAM hive from Volume Shadow Copy locations using .NET or PowerShell copy semantics.
sigmaWindowshigh2021-07-29Windows Process Creation: Automated Document and Directory Discovery via dir and findstr
Flags Windows commands combining recursive dir listing, FINDSTR usage, and document-type targeting in one execution.
sigmaWindowsmedium2021-07-28PowerShell Script Block Collection of Documents via Recursive Get-ChildItem
Alerts on PowerShell file enumeration that recursively searches and includes common document extensions via Get-ChildItem.
sigmaWindowsmedium2021-07-28Windows: WinZip executed with password flag and archive parameters indicative of data staging
Flags Windows executions of WinZip/WinZip64 using a password flag and archive parameters that can support data staging.
sigmaWindowsmedium2021-07-27Windows: clip.exe Execution to Copy Data to Clipboard
Flags execution of clip.exe on Windows, a common utility for copying data into the clipboard.
sigmaWindowslow2021-07-27Windows: 7-Zip password-protected archive creation for potential data exfiltration
Flags 7-Zip archive creation on Windows with a password flag and archive-action parameters.
sigmaWindowsmedium2021-07-27Windows nltest.exe Recon via Server Query and Domain Trust Enumeration
Alerts on nltest.exe commands with server/query and domain trust enumeration arguments often used for Windows discovery.
sigmaWindowsmedium2021-07-24Windows Hacktool Execution Indicators for SMB/NTLM Relay and Potato-Style Privilege Escalation
Alerts on Windows execution of common SMB/NTLM relay and “Potato” privilege escalation hacktool indicators via process creation fields.
sigmaWindowscritical2021-07-24Windows Process Creation: Impacket HackTool Binary Execution via Named Image Matches
Flags execution of Windows impacket compiled binaries based on distinctive tool names in the process Image.
sigmaWindowshigh2021-07-24Windows File Writes of HiveNightmare-Style SAM Export Artifacts
Identifies Windows SAM export files written with HiveNightmare-style filename patterns in file events.
sigmaWindowshigh2021-07-23Windows Registry Changes Enabling DNS-over-HTTPS via Edge, Chrome, or Firefox Policies
Alerts on registry policy updates that enable DNS-over-HTTPS for Edge, Chrome, or Firefox on Windows.
sigmaWindowsmedium2021-07-22Windows Process Creation: Netcat (ncat/cat) Suspicious Execution
Alerts on Windows process launches of Netcat-like binaries with typical listener/proxy or remote execution command-line flags.
sigmaWindowshigh2021-07-21