Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell via sqltoolsps.exe (sqltoolsps.exe child process exclusion)
Flags suspicious sqltoolsps.exe executions that may launch PowerShell, excluding cases where smss.exe spawned the utility.
sigmaWindowsmedium2020-10-13Windows manage-bde.wsf via wscript/cscript Proxy Execution
Flags Windows process executions where wscript/cscript runs manage-bde.wsf, indicating potential proxy execution via LOLBIN.
sigmaWindowshigh2020-10-13Windows Process Command Line: Detect VAR++ LAUNCHER Obfuscated PowerShell
Flags Windows command lines showing VAR++ launcher-style obfuscated PowerShell execution through Invoke-Expression patterns.
sigmaWindowshigh2020-10-13Windows Process Creation: Obfuscated Cmd Uses clip.exe to Execute PowerShell
Alerts when cmd.exe uses obfuscated Clip.exe/clipboard calls to launch PowerShell.
sigmaWindowshigh2020-10-13Detect VAR++ LAUNCHER-Style Obfuscated PowerShell Command Block
Detects VAR++ LAUNCHER-like PowerShell obfuscation patterns in ScriptBlockText.
sigmaWindowshigh2020-10-13PowerShell Script Block Obfuscation via cmd/clipboard and clip.exe execution
Identifies obfuscated PowerShell script blocks launching clip.exe and chaining clipboard-related execution.
sigmaWindowshigh2020-10-13PowerShell Module: VAR++ LAUNCHER Obfuscation in Obfuscated Command Payload
Identifies obfuscated PowerShell module payloads matching a VAR++ LAUNCHER-style invocation pattern.
sigmaWindowshigh2020-10-13PowerShell Module: Obfuscated Clip.exe launcher using cmd with clipboard download payload
Detects obfuscated PowerShell module commands that run cmd with clip.exe/clipboard payload formatting.
sigmaWindowshigh2020-10-13Windows System: Detects Service Control Manager spawning obfuscated PowerShell via VAR++ LAUNCHER
Flags newly created Windows services whose ImagePath contains cmd chaining and obfuscated PowerShell launcher indicators.
sigmaWindowshigh2020-10-13Windows System Service Control: Obfuscated cmd Launching clip.exe for PowerShell
Flags service creation (Event 7045) with obfuscated cmd ImagePath using clip.exe/clipboard PowerShell execution patterns.
sigmaWindowshigh2020-10-13Windows Zerologon Exploitation Attempts via Mimikatz or Tools from Kali Host
Identifies Windows Zerologon exploitation attempts tied to Kali-hosted activity and mimikatz-related keywords.
sigmaWindowscritical2020-10-13Windows Security 4697 Alert for Obfuscated PowerShell Invoke via VAR++ LAUNCHER
Alerts on obfuscated PowerShell launcher patterns in Windows service creation events (EID 4697) consistent with VAR++ LAUNCHER.
sigmaWindowshigh2020-10-13Windows Security Log: Obfuscated cmd Execution of clip.exe via PowerShell Clipboard Patterns (EID 4697)
Alerts on service creation (Windows 4697) with CLIP.exe command-line patterns that indicate obfuscated PowerShell execution.
sigmaWindowshigh2020-10-13Windows Proxy Execution via wuauclt.exe (UpdateDeploymentProvider/RunHandlerComServer)
Alerts when wuauclt.exe is executed with UpdateDeploymentProvider/RunHandlerComServer-related parameters indicative of proxy execution.
sigmaWindowshigh2020-10-12Windows WMIC process creation with suspicious command execution
Alerts on WMIC spawning new processes with command-line indicators of common execution/payload binaries on Windows.
sigmaWindowshigh2020-10-12Windows regini.exe Used to Modify Registry via Alternate Data Streams (ADS)
Alert on regini.exe process executions whose command line contains an ADS-style colon pattern used for registry modification.
sigmaWindowshigh2020-10-12Windows: regedit.exe imports .reg via an alternate data stream (ADS)
Alerts when regedit.exe is used to import a .reg file using an alternate data stream pattern in the command line.
sigmaWindowshigh2020-10-12Windows Regedit Exports Registry Hives to Files
Flags regedit.exe command lines exporting SYSTEM/SAM/SECURITY hives from HKLM to files.
sigmaWindowshigh2020-10-12Windows Process Creation: PowerShell or sc.exe Disabling Windows Defender Behavior Monitoring
Detects PowerShell flags or sc.exe service actions that disable WinDefend monitoring on Windows.
sigmaWindowshigh2020-10-12Windows Indirect Command Execution via Program Compatibility Assistant pcwrun.exe
Alerts on child processes spawned by pcwrun.exe, indicating indirect command execution via Program Compatibility Assistant.
sigmaWindowslow2020-10-12