Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
sigmaWindowshigh2021-05-26Windows Named Pipe Creation Matching Cobalt Strike Default Pipe Prefixes
Flags Windows named pipe creation where PipeName matches known Cobalt Strike default pipe prefixes.
sigmaWindowscritical2021-05-25Windows Process Creation: PsExec/PAExec Flags Indicating SYSTEM Execution
Flags indicating PsExec/PAExec-style execution as LOCAL SYSTEM using cmd/powershell/pwsh in process command lines.
sigmaWindowshigh2021-05-22Windows Process Creation: Renamed PAExec Application Execution
Flags Windows executions of a renamed PAExec binary using process metadata and known IMPHASH values.
sigmaWindowshigh2021-05-22Windows: WinRM Service Process Spawning Command-Line and Scripting Utilities
Flags suspicious child shells and admin utilities spawned by the WinRM host process (wsmprovhost.exe) on Windows.
sigmaWindowshigh2021-05-20PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
sigmaWindowshigh2021-05-18Windows Process Command Lines Indicating ngrok.exe Tunnel Setup
Detects Windows executions of ngrok.exe with TCP/HTTP tunneling and authtoken/start-all YAML configuration patterns.
sigmaWindowshigh2021-05-14Windows: Detect Rclone command execution with exfiltration-oriented flags
Identifies likely rclone.exe exfiltration activity on Windows by matching command-line flags and rclone executable characteristics.
sigmaWindowshigh2021-05-10Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)
Alerts on creation of the "ZzNetSvc" service by Service Control Manager (Event ID 7045) on Windows.
sigmaWindowscritical2021-05-06Windows whoami.exe Privilege Enumeration Using /priv Flag
Alerts on whoami.exe runs with /priv or -priv to enumerate current user privileges.
sigmaWindowshigh2021-05-05Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
sigmaWindowshigh2021-05-03Windows Security: Hidden Local User Account Creation (Event ID 4720)
Alerts on Windows 4720 local user creation for hidden accounts (username ending with '$'), excluding 'HomeGroupUser$'.
sigmaWindowshigh2021-05-03Windows Process Access to svchost.exe with Credential Dumping Access Rights
Alerts on attempts to read svchost.exe memory consistent with credential dumping, excluding known benign callers.
sigmaWindowshigh2021-04-30PowerShell Defender Exclusion via Set/Add-MpPreference Command-Line Flags (Windows)
Detects PowerShell commands that add or set Microsoft Defender exclusions using Add/Set-MpPreference parameters.
sigmaWindowsmedium2021-04-29Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
sigmaWindowshigh2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
sigmaWindowshigh2021-04-23PowerShell ScriptBlock Certificate Export via Export-PfxCertificate or Export-Certificate
Detects PowerShell script blocks invoking certificate export cmdlets, which may be abused to steal sensitive certificate material.
sigmaWindowsmedium2021-04-23Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Flags HybridConnectionManager-initiated DNS queries to servicebus.windows.net on Windows.
sigmaWindowshigh2021-04-12Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)
Flags Windows Hybrid Connection Manager-related events mentioning sb:// and servicebus.windows.net.
sigmaWindowshigh2021-04-12Windows Security Event 4697: HybridConnectionManager Service Installation
Alerts on HybridConnectionManager service installation on Windows via Security Event ID 4697.
sigmaWindowshigh2021-04-12