Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Command-Line Disables Volume Shadow Copy (VSS) Snapshots
Flags Windows command lines that disable Volume Shadow Copy (VSS) snapshots via VSS Diag service switches.
sigmaWindowshigh2021-01-28Windows Process Creation: Raccine Removal via taskkill, registry and scheduled task deletion
Detects command-line activity that stops and removes Raccine components through process killing, registry deletion, and scheduled task removal.
sigmaWindowshigh2021-01-21Windows Service Installation (EID 4697) for SMB PsExec by Metasploit or Impacket
Alerts on Windows Event ID 4697 service installs matching SYSTEMROOT\8char.exe and on-demand start, consistent with PsExec-style SMB execution.
sigmaWindowshigh2021-01-21Windows Plink Remote Port Forwarding via -R Command Line
Alerts on Windows process command lines using Plink " -R " remote port forwarding to a local port.
sigmaWindowshigh2021-01-19Windows System Log: NTFS File System Driver Event 55 Indicates Possible NTFS Exploitation
Alerts on Windows NTFS Event ID 55 indicating a corrupted file record with a matching filename string in the event description.
sigmaWindowshigh2021-01-11Windows Registry Persistence via VSTO Add-ins in Microsoft Office
Flags registry writes that register VSTO/Office add-ins for Outlook, Word, Excel, or PowerPoint persistence on Windows.
sigmaWindowsmedium2021-01-10Windows: Suspicious Child Processes Spawned by sqlservr.exe
Alerts when SQL Server (sqlservr.exe) spawns suspicious command/system tools on Windows.
sigmaWindowshigh2020-12-11Windows Registry Run Key Modification via winekey or team9 backdoor
Detects registry Run key changes to "Backup Mgr" that may indicate persistence via winekey/team9.
sigmaWindowshigh2020-10-30Windows PsExec Execution Triggered by psexec.exe Process Creation
Flags process creation of PsExec (psexec.exe / psexec.c), a tool often used for remote execution and potential lateral movement.
sigmaWindowsmedium2020-10-30Windows Credential Access via Reg Add in LSA Registry Paths
Alerts when reg add commands target LSA registry settings and scecli entries commonly abused for credential access.
sigmaWindowsmedium2020-10-29Windows Process Creation: bitsadmin.exe BITS jobs with SetNotifyCmdLine or remote file additions
Alerts on bitsadmin.exe command lines using /SetNotifyCmdLine or /Addfile to execute after download or stage remote files.
sigmaWindowsmedium2020-10-29Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
sigmaWindowshigh2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
sigmaWindowshigh2020-10-29Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
sigmaWindowshigh2020-10-28Windows Registry Persistence via Office Test Startup Key
Flags registry changes to a Windows Office test startup key that may enable auto-execution of an arbitrary DLL.
sigmaWindowsmedium2020-10-25Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32
Alerts on suspicious Windows process launches of key binaries with missing/empty arguments, excluding common Edge/Chromium installer use.
sigmaWindowshigh2020-10-23Windows Registry: Detect esentutl.exe activity under VSS service keys
Flags registry changes under VSS service keys when initiated by esentutl.exe, consistent with VSS-related abuse.
sigmaWindowshigh2020-10-20Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
sigmaWindowshigh2020-10-20Windows DLL image load: credui.dll loaded by an uncommon process
Detects credui.dll or wincredui.dll being loaded by a process other than common system binaries.
sigmaWindowsmedium2020-10-20Windows Event Log Detects Volume Shadow Copy Mounts (HarddiskVolumeShadowCopy, EventID 98)
Alerts when NTFS logs indicate a VSS (HarddiskVolumeShadowCopy) mount using EventID 98.
sigmaWindowslow2020-10-20