Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Security: VSSAudit Event Source Registration (Event ID 4904/4905)
Alerts on VSSAudit security event source registration in Windows Security logs using Event IDs 4904/4905.
sigmaWindowsinformational2020-10-20Windows RunOnce Execution via runonce.exe With AlternateShellStartup and /r
Alerts on runonce.exe executing with /AlternateShellStartup and /r, consistent with configured RunOnce persistence behavior.
sigmaWindowslow2020-10-18Windows Process Execution and DLL Injection via Tracker.exe
Alerts on Tracker.exe executions with /d and /c command-line switches, excluding matching MSBuild child process patterns.
sigmaWindowsmedium2020-10-18Windows: msdeploy.exe Execution with sync and RunCommand Parameters
Flags msdeploy.exe executions that include sync verb plus RunCommand source and destination parameters.
sigmaWindowsmedium2020-10-18Windows PowerShell Process Creation: COMPRESS OBFUSCATION with ASCII Encoding and DeflateStream
Flags PowerShell process creation command lines that use ASCII encoding plus compression/stream-reading patterns associated with obfuscation.
sigmaWindowsmedium2020-10-18Windows: Dotnet.exe executes arbitrary DLL or csproj files
Alerts when dotnet.exe runs with .csproj or .dll arguments that may indicate loading or execution of untrusted .NET code.
sigmaWindowsmedium2020-10-18PowerShell ScriptBlock Logging: Obfuscated RUNDLL Launcher using rundll32.exe and shell32.dll
Identifies PowerShell script content invoking rundll32.exe/shell32.dll via shellexec_rundll and referencing PowerShell.
sigmaWindowsmedium2020-10-18Detect PowerShell COMPRESS OBFUSCATION using ASCII text encoding and stream/compression APIs
Flags PowerShell script blocks that combine ASCII encoding with Deflate/stream handling indicative of obfuscated payload compression.
sigmaWindowsmedium2020-10-18PowerShell module activity launching rundll32 via shell32.dll obfuscation content
Alerts when PowerShell module payloads reference a shell32/rundll32 launcher pattern that includes PowerShell.
sigmaWindowsmedium2020-10-18PowerShell Module Payload Obfuscation Using COMPRESS OBFUSCATION
Identifies PowerShell module payloads containing ASCII encoding and compression/stream obfuscation strings.
sigmaWindowsmedium2020-10-18Windows System: Detect rundll32 Service Control Manager launches PowerShell via obfuscated parameters
Flags service creation where ImagePath uses rundll32/shell32 (shellexec_rundll) to invoke PowerShell.
sigmaWindowsmedium2020-10-18Windows System: Service Control Manager PowerShell Obfuscation Using COMPRESS OBFUSCATION
Flags new Windows services whose ImagePath includes obfuscated PowerShell markers using COMPRESS/stream decompression.
sigmaWindowsmedium2020-10-18Windows Security 4697: Obfuscated PowerShell via rundll32 shell32 shellexec_rundll
Alert on Security EID 4697 where service installation references rundll32/shell32.dll to launch PowerShell.
sigmaWindowsmedium2020-10-18Windows Security 4697 PowerShell obfuscated content using COMPRESS OBFUSCATION components
Alerts on service creation events where the ServiceFileName includes PowerShell obfuscation patterns tied to compression stream and ASCII encoding.
sigmaWindowsmedium2020-10-18Windows PowerShell Script Execution via Redirected Input Stream
Flags PowerShell/pwsh executions where the command line includes redirected input ("- <").
sigmaWindowshigh2020-10-17Windows Process Creation: Suspicious Microsoft Csi.exe or Rcsi.exe with C# Execution Capability
Alerts on Windows executions of Microsoft’s csi.exe/rcsi.exe that can be used to run C# code from command-line.
sigmaWindowsmedium2020-10-17Windows WMIC loading JavaScript/VBScript engine libraries
Alerts on wmic.exe loading jscript.dll or vbscript.dll, a common sign of script execution via Windows Management Instrumentation.
sigmaWindowsmedium2020-10-17Potential Windows Registry Persistence via AppCompatFlags TelemetryController Commands
Flags registry entries under TelemetryController\Command that reference executable/script payloads potentially abusing telemetry for persistence.
sigmaWindowshigh2020-10-16Windows sc.exe Security Descriptor Tampering to Deny Service Access via sdset
Alerts on sc.exe sdset commands that modify service security descriptors to deny access to critical trustees.
sigmaWindowshigh2020-10-16Windows Process: reg.exe Software Version Discovery via svcVersion Query
Alerts when reg.exe is used to query \Software\ for svcVersion, indicating Windows software version discovery.
sigmaWindowsmedium2020-10-16