Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry Changes for Outlook WebView Home Page URL Persistence
Alerts on Windows registry modifications affecting Outlook WebView home page URL settings.
sigmaWindowshigh2021-06-09Windows Registry: Microsoft Office Protected View Disabled via Security Policy Keys
Flags Windows registry updates that disable Microsoft Office Protected View for attachments, internet files, UNC paths, or unsafe locations.
sigmaWindowshigh2021-06-08Windows Process Creation: Exchange Transport Agent Installation via Install-TransportAgent
Flags Windows command-line executions containing Install-TransportAgent, indicating Exchange Transport Agent installation activity.
sigmaWindowsmedium2021-06-08Windows MSExchange: Failed Transport Agent Installation (Install-TransportAgent)
Alerts on EventID 6 Exchange management events that include "Install-TransportAgent", indicating a failed Transport Agent installation attempt.
sigmaWindowshigh2021-06-08Windows MSExchange Transport Agent Installation via Install-TransportAgent
Flags Exchange Transport Agent installation attempts using the Install-TransportAgent command in MSExchange management telemetry.
sigmaWindowsmedium2021-06-08Windows AMSI Provider Registry Key Deletion (HKLM\Software\Microsoft\AMSI)
Alerts on deletion of AMSI provider registry key entries under HKLM\Software\Microsoft\AMSI, potentially indicating AMSI inspection impairment.
sigmaWindowshigh2021-06-07PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
sigmaWindowshigh2021-06-07Windows Sysmon Configuration Event Where Sysmon Stops
Alert on Sysmon status showing a stop event concurrent with a Sysmon configuration state change.
sigmaWindowshigh2021-06-04Windows Sysmon error events indicating service configuration update failures
Flags Windows Sysmon errors for failed service configuration/driver update attempts that may indicate tampering.
sigmaWindowshigh2021-06-04Windows Process Creation: SDelete Used for File Overwrite
Alerts when sdelete.exe runs in a way consistent with file overwrite to impede forensic recovery.
sigmaWindowshigh2021-06-03Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
sigmaWindowshigh2021-06-03Windows Rundll32 Loads DLL Export StartNodeRelay (F-Secure C3)
Flags rundll32.exe launching a DLL that references the StartNodeRelay export in its command line.
sigmaWindowscritical2021-06-02Windows Rundll32 Used to Start Cobalt Strike DLL Load via StartW
Alerts on rundll32.exe command lines that include a .dll and StartW function, consistent with Cobalt Strike DLL loading.
sigmaWindowshigh2021-06-01Windows Security Event 4663: ISO CD-ROM device mount activity
Alerts on Windows file-access events consistent with ISO mounting by activity under \\Device\\CdRom.
sigmaWindowsmedium2021-05-29Windows rundll32.exe Started Without Command-Line Parameters
Alerts on Windows process launches of rundll32.exe with no parameters, excluding likely benign parent paths.
sigmaWindowshigh2021-05-27Windows: regedit.exe launched with TrustedInstaller or Process Hacker parent
Alerts when regedit.exe is launched by TrustedInstaller.exe or ProcessHacker.exe.
sigmaWindowshigh2021-05-27Windows Service Control Manager: ProcessHacker service runs as LocalSystem
Flags Windows service installs for ProcessHacker-prefixed services running as LocalSystem.
sigmaWindowshigh2021-05-27Windows: Rclone Configuration File Creation via rclone config path
Alerts on creation of rclone config files under a Windows user profile path.
sigmaWindowsmedium2021-05-26Windows DNS Queries for userstorage.mega.co.nz Subdomain
Alerts on DNS queries referencing MEGA userstorage subdomains from Windows hosts.
sigmaWindowsmedium2021-05-26Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Alerts on Windows 7045 service installs with ImagePath patterns consistent with Cobalt Strike-style PowerShell and execution.
sigmaWindowscritical2021-05-26