Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows PowerShell Web Access Installation via PowerShell Script Block
Detects PowerShell Web Access installation and web authorization configuration from Windows PowerShell script blocks.
sigmaWindowshigh2024-09-03Windows Process Deletes Its Own Executable File
Flags Windows file deletion events where a process removes its own executable image.
sigmaWindowsmedium2024-09-03Windows Incoming AnyDesk Connection via AnyDesk.exe or AnyDeskMSI.exe
Alerts on non-initiated (incoming) network connections tied to AnyDesk.exe or AnyDeskMSI.exe on Windows.
sigmaWindowsmedium2024-09-02Windows Registry: Disable Python function execution warnings in Excel
Alerts on registry updates that disable Excel Python function execution warnings via the PythonFunctionWarnings DWORD.
sigmaWindowshigh2024-08-23Windows DNS Client detects queries to Put.io subdomains (api.put.io, upload.put.io)
Alert on Windows DNS Client queries containing api.put.io or upload.put.io.
sigmaWindowsmedium2024-08-23Windows Process Creation: BCP.EXE Used to Export SQL Data
Flags Windows executions of bcp.exe where command-line options indicate MSSQL data export via out/queryout.
sigmaWindowsmedium2024-08-20Windows Process Masquerading as svchost.exe via Binary Name and Location
Alerts on svchost.exe-named processes launched from non-standard paths with OriginalFileName svchost.exe.
sigmaWindowshigh2024-08-07Windows File Access to Cryptocurrency Wallet Keystores by Uncommon Processes
Alerts on access to Ethereum/Bitcoin-style wallet files from non-standard processes on Windows.
sigmaWindowsmedium2024-07-29Windows Process Creation Ending in .exe With No Image Name
Flags Windows process creation events where the .exe path exists but the image name is missing, indicating possible stealth or evasion.
sigmaWindowsmedium2024-07-23Windows: Detect execution of renamed BOINC.exe binary
Flags renamed BOINC executables on Windows by matching OriginalFileName=BOINC.exe when the executed image name differs.
sigmaWindowsmedium2024-07-23PowerShell Launch With --headless From Conhost.exe on Windows
Flags headless ConHost launching PowerShell on Windows based on process name and command-line arguments.
sigmaWindowsmedium2024-07-23Windows: Uncommon Process Access to Microsoft Teams Cookies or Local Storage leveldb
Alerts on access to Teams Cookies or leveldb files by processes other than Teams.exe on Windows.
sigmaWindowsmedium2024-07-22Windows COM CLSID Hijacking via Registry Default InprocServer32/LocalServer32 Modification
Detects registry changes to COM CLSID Default InprocServer32/LocalServer32 values that point to suspicious locations.
sigmaWindowshigh2024-07-16Windows Process Creation: Renamed Microsoft Teams Executable Launch
Alerts when Microsoft Teams binaries are launched under renamed executable names on Windows.
sigmaWindowsmedium2024-07-12Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Alerts when DsrmAdminLogonBehavior registry value is changed on Windows, except the default DWORD 0x00000000.
sigmaWindowshigh2024-07-11Windows Process Execution of BitLockerToGo.EXE
Alerts on Windows execution of BitLockerToGo.exe, a rarely used BitLocker To Go component for portable drive encryption.
sigmaWindowslow2024-07-11Windows DLL Sideloading Suspected for ms<wbr>corsvc.dll via ImageLoad
Alerts on non-standard loads of msocrsvc.dll, a potential DLL sideloading opportunity on Windows.
sigmaWindowsmedium2024-07-11Windows DLL Sideloading via MpSvc.dll Image Load Anomaly
Flags Windows module loads of MpSvc.dll outside typical Defender/WinSxS locations that may indicate DLL sideloading.
sigmaWindowsmedium2024-07-11Potential DLL Sideloading: Image Load of DbgModel.dll on Windows
Alerts when a process loads DbgModel.dll from a non-standard path, suggesting possible DLL sideloading.
sigmaWindowsmedium2024-07-11Windows: Detect regedit.exe creating a PDF file
Alerts when RegEdit.exe creates a .pdf file on Windows.
sigmaWindowshigh2024-07-08