Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Injection via Mavinject Using INJECTRUNNING Flag
Alerts on Windows process creation using Mavinject with /INJECTRUNNING, indicative of DLL injection into a running process.
sigmaWindowshigh2021-07-12Windows spoolsv.exe Child Process Execution Indicators
Flags suspicious process executions where spoolsv.exe (print spooler) spawns utility, scripting, or rundll32 children with high integrity.
sigmaWindowshigh2021-07-11Windows DNS Queries for IP Lookup Service Domains from Non-Browser Processes
Flags suspicious DNS lookups to IP-check API domains on Windows when they come from non-browser executables.
sigmaWindowsmedium2021-07-08Windows Process Creation: MpCmdRun.exe Removing All Windows Defender Definitions
Flags MpCmdRun.exe launched to remove all Windows Defender definition files.
sigmaWindowshigh2021-07-07Windows Registry Defender Exclusions Path Set (Microsoft\Windows Defender\Exclusions)
Identifies registry updates that reference the Windows Defender Exclusions path, indicating potential defense impairment.
sigmaWindowsmedium2021-07-06Windows Defender Exclusions Added via Windefend (Event ID 5007)
Alerts on Windows Defender exclusion additions based on windefend Event ID 5007 configuration change events.
sigmaWindowsmedium2021-07-06Windows windefend: Detect Tamper Protection blocks changes to Microsoft Defender settings
Flags Defender tamper protection blocks to disable key Microsoft Defender Antivirus and real-time protection settings.
sigmaWindowshigh2021-07-05Windows SMB Client Security: Rejected Guest Logon with Blank UserName
Flags rejected SMB guest/anonymous-style logons on Windows when the SMB username is blank.
sigmaWindowsmedium2021-06-30Windows Registry Service Install Indicators for Cobalt Strike Staging
Identifies suspicious Windows service installation registry writes tied to ADMIN$/.exe and %COMSPEC% start powershell patterns.
sigmaWindowshigh2021-06-29Windows reg.exe Run Key Modification for Persistence via Process Creation
Alerts on reg.exe commands that add values to Windows Run registry keys, a common persistence technique.
sigmaWindowsmedium2021-06-28Windows Process Creation: WMIC.exe ActiveScriptEventConsumer Creation Attempt
Alerts on WMIC.exe command lines attempting to create an ActiveScriptEventConsumer for event-driven script execution.
sigmaWindowshigh2021-06-25Windows PortProxy Registry Key Modified for Port Forwarding
Alerts when PortProxy port-forwarding registry entries under the Windows TCP v4tov4 path are added or modified.
sigmaWindowsmedium2021-06-22Windows: Detect execution of renamed megasync.exe (original MegaSync) via process creation
Flags process launches where megasync.exe appears under a renamed or nonstandard execution context based on process creation fields.
sigmaWindowshigh2021-06-22Windows LDAP Client Event ID 30 Active Directory enumeration via LDAP search filters
Flags LDAP search queries indicative of Active Directory reconnaissance/enumeration using Event ID 30 filter patterns.
sigmaWindowsmedium2021-06-22Windows: Suspicious Child Process Spawned by scrcons.exe (Script Event Consumer)
Alerts on rare child processes spawned by scrcons.exe, which may indicate abuse of Script Event Consumer for execution.
sigmaWindowshigh2021-06-21Windows Registry: New TaskCache entry created by unusual process image
Alerts when TaskCache registry entries are created by processes other than a defined set of expected Windows binaries.
sigmaWindowshigh2021-06-18Windows Execution of PurpleSharp HackTool by Image Name or Executable Metadata
Alerts on process creation events consistent with running PurpleSharp.exe on Windows.
sigmaWindowscritical2021-06-18Windows: Process writes registry to disable storage write-protection
Alerts on Windows process command lines that appear to disable storage write-protection via registry modification.
sigmaWindowsmedium2021-06-11Windows Registry Set—Custom Outlook Today Page for Persistence
Flags registry writes that configure a custom Outlook Today URL using Outlook Today registry values.
sigmaWindowshigh2021-06-10Windows Persistence Attempt Using Outlook.exe to Create Outlook Forms Cache
Flags Outlook (outlook.exe) form file activity targeting local FORMS directories often used for persistence.
sigmaWindowshigh2021-06-10