Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell Script Block Local Email Collection via Outlook COM Automation
Flags PowerShell script block text referencing Outlook COM automation used to collect locally stored email.
sigmaWindowsmedium2021-07-21PowerShell command line containing powercat invocation on Windows
Alerts when classic PowerShell starts with Powercat-related command-line strings ('powercat ' or 'powercat.ps1').
sigmaWindowsmedium2021-07-21Windows Private Key File Recon via cmd.exe, PowerShell, or findstr.exe
Flags Windows command-line searches for key/certificate file extensions using cmd.exe, PowerShell, or findstr.
sigmaWindowsmedium2021-07-20PowerShell Compress-Archive Creates Archive in Temp or System Temp Paths
Flags PowerShell Compress-Archive usage writing archives to %TEMP%, AppData Local Temp, or Windows Temp.
sigmaWindowsmedium2021-07-20PowerShell: Compress-Archive to TEMP/AppData/Windows Temp for Staging
Flags PowerShell scripts compressing data with Compress-Archive into $env:TEMP or Temp folders.
sigmaWindowsmedium2021-07-20Windows PowerShell module usage: Compress-Archive to store archives in Temp locations
Alerts on PowerShell Compress-Archive output written to common temp staging directories.
sigmaWindowsmedium2021-07-20PowerShell Classic Compress-Archive staging in TEMP or Temp directories
Alerts on PowerShell Compress-Archive output targeting common Temp directories for data staging.
sigmaWindowsmedium2021-07-20Windows mshta.exe Process Creation Triggered by Suspicious Command Lines
Alert on mshta.exe launches from suspicious parents and script-like command lines/paths.
sigmaWindowshigh2021-07-17Windows Process Execution of SyncAppvPublishingServer.vbs with Inline PowerShell Commands
Flags Windows executions of SyncAppvPublishingServer.vbs with a semicolon-augmented command line consistent with embedded PowerShell.
sigmaWindowsmedium2021-07-16PowerShell executes ADRecon.ps1 AD reconnaissance functions and writes ADRecon-Report.xlsx
Detects PowerShell ADRecon reconnaissance script content by matching AD discovery functions and the default ADRecon report output name.
sigmaWindowshigh2021-07-16Windows: Suspicious Parent-Serv-U.exe Command-Line Process Spawning
Alerts when Serv-U (\Serv-U.exe) spawns typical command interpreters or execution utilities on Windows.
sigmaWindowshigh2021-07-14Windows reg.exe Used to Modify Security Service Start Parameters
Flags reg.exe registry changes that target Start parameters for common security and Windows Defender-related services.
sigmaWindowshigh2021-07-14Suspicious PowerShell Execution From Windows Temporary Folders on Windows
Alerts when PowerShell runs with command-line paths pointing to Windows temp directories, excluding some common benign installers.
sigmaWindowsmedium2021-07-14Windows ProtocolHandler.exe Download via Embedded URL Schemes
Flags ProtocolHandler.exe executions with ftp/http/https URLs that indicate automated downloading on Windows.
sigmaWindowsmedium2021-07-13Windows PowerShell: AtomicTestHarness Invoke-ATHRemoteFXvGPUDisablementCommand Abuse
Alerts on Windows process command lines invoking AtomicTestHarnesses RemoteFXvGPUDisablement PowerShell execution.
sigmaWindowshigh2021-07-13Windows: InfDefaultInstall.exe .inf Execution
Flags Windows process executions of InfDefaultInstall.exe that include an .inf argument in the command line.
sigmaWindowsmedium2021-07-13Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
Flags PowerShell module creation where ModuleContents includes Get-VMRemoteFXPhysicalVideoAdapter.
sigmaWindowshigh2021-07-13Windows PowerShell ModuleContents Set to Get-VMRemoteFXPhysicalVideoAdapter
Alerts on PowerShell module creation embedding Get-VMRemoteFXPhysicalVideoAdapter, a potential precursor to RemoteFXvGPUDisablement.exe abuse.
sigmaWindowshigh2021-07-13Windows Uninstall CrowdStrike Falcon Sensor via WindowsSensor.exe /uninstall /quiet
Flags Windows processes uninstalling CrowdStrike Falcon Sensor using WindowsSensor.exe with /uninstall and /quiet.
sigmaWindowshigh2021-07-12Windows Process: SyncAppvPublishingServer.exe Executes PowerShell via PowerShell-encoded command
Alerts when SyncAppvPublishingServer.exe is launched with a command-line pattern indicative of PowerShell code execution.
sigmaWindowsmedium2021-07-12