Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Registry: Outlook Macro Security Level Set to Enable All Macros
Detects Outlook macro warning bypass by setting the Outlook security level registry value to enable all macros.
sigmaWindowshigh2021-04-05Windows Persistence: Outlook LoadMacroProviderOnBoot Registry Setting Modification
Alerts on enabling the Outlook LoadMacroProviderOnBoot registry setting, which can allow automatic VBA module loading at startup.
sigmaWindowshigh2021-04-05Windows: New Outlook VBAProject OTM Macro File Created
Flags Windows file creation of Outlook VBAProject.OTM when initiated by outlook.exe.
sigmaWindowsmedium2021-04-05Windows Exchange Management: Set-OabVirtualDirectory ExternalUrl to script content
Detects Exchange Management changes to OAB ExternalUrl containing script indicators and Page_Load.
sigmaWindowshigh2021-03-15Windows schtasks.exe Creating One-Time Scheduled Tasks Using Temp Folder
Alerts on schtasks.exe commands that create one-time scheduled tasks referencing a Temp directory.
sigmaWindowshigh2021-03-11Windows: Suspicious Service Binary Executed from Public/System Directories
Alerts on service-hosted processes executing from user/public or system-writable directories on Windows.
sigmaWindowshigh2021-03-09Windows Registry: VBScript/HTMLApplication Payload Stored Under Run Keys
Flags registry persistence where script payload indicators like vbscript: and RunHTMLApplication appear in set registry values.
sigmaWindowshigh2021-03-05Windows Process Creation: rundll32.exe Command Line Invoking .sys Files
Flags Windows rundll32.exe executions whose command line references .sys file patterns.
sigmaWindowshigh2021-03-05Windows rundll32 Executing Inline VBScript via RegRead
Detects rundll32.exe command lines containing inline VBScript execution with RegRead and window.close.
sigmaWindowshigh2021-03-05Windows Process Creation: Exchange PowerShell Snap-in Loading via Add-PSSnapin
Flags PowerShell executions that Add-PSSnapin Exchange snap-ins, consistent with Exchange mailbox/config data collection.
sigmaWindowshigh2021-03-03Windows PowerShell TcpClient reverse-shell connection attempt via Net.Sockets
Alerts on PowerShell processes launching with .NET TcpClient stream/write patterns consistent with reverse TCP connectivity.
sigmaWindowshigh2021-03-03Windows Registry: SilentProcessExit lsass.exe Monitor Registration for Credential Dumping
Alerts on registry registrations for SilentProcessExit monitoring of lsass.exe, a potential precursor to credential dumping.
sigmaWindowscritical2021-02-26Windows Process Creation: finger.exe Execution
Alerts on Windows executions of finger.exe, a legacy utility that may indicate suspicious reconnaissance or network activity.
sigmaWindowshigh2021-02-24Windows ScreenConnect Installation Execution via Remote Access Parameters
Flags Windows executions of ScreenConnect with remote access command-line parameters indicating remote session setup.
sigmaWindowsmedium2021-02-11Windows Process Creation: logman.exe Used to Stop or Delete ETW Trace Sessions
Alerts when logman.exe is used to stop or delete Windows ETW trace sessions.
sigmaWindowshigh2021-02-11Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Detects AdFind executions on Windows that include common AD reconnaissance parameters.
sigmaWindowshigh2021-02-02Windows Audit Policy Tampering Using auditpol.exe Command-Line Flags
Flags auditpol.exe executions that disable, clear, remove, or restore Windows audit policy settings.
sigmaWindowshigh2021-02-02Windows Process Creation: Detect ShimCache Flush via rundll32 apphelp.dll/kernel32.dll
Flags rundll32 command-line activity that flushes ShimCache via apphelp.dll or kernel32.dll entry points.
sigmaWindowshigh2021-02-01Windows rundll32.exe execution with no parameters or arguments
Alerts on Windows rundll32.exe being started with an empty/no-parameter command line.
sigmaWindowshigh2021-01-31Windows WMIC Uninstall/Terminate Actions Targeting Security Products
Flags WMIC commands on Windows that attempt to uninstall or terminate security products or sensors using known vendor/product strings.
sigmaWindowshigh2021-01-30