Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows verclsid.exe executes COM object via GUID parameters
Flags verclsid.exe process launches using /S /C COM GUID-style arguments on Windows.
sigmaWindowsmedium2020-10-09Windows: Identify RpcPing.exe -s RPC test that requests NTLM authentication
Detects RpcPing.exe RPC test usage with parameters indicating NTLM authentication attempts.
sigmaWindowsmedium2020-10-09Windows Renamed ftp.exe Execution via OriginalFileName PE Metadata
Flags Windows executions where PE OriginalFileName is ftp.exe but the image path is not named ftp.exe.
sigmaWindowsmedium2020-10-09Suspicious WINWORD.exe DLL loading via /l flag and .dll path on Windows
Flags WINWORD.exe runs that include /l and a .dll indicator, suggesting potential DLL sideloading on Windows.
sigmaWindowsmedium2020-10-09Windows: Detect Runscripthelper.exe executing PowerShell scripts with 'surfacecheck'
Detects Runscripthelper.exe executions with "surfacecheck" in the command line on Windows.
sigmaWindowsmedium2020-10-09Windows Rasautou.exe DLL loading with -d and export execution via -p
Flags Rasautou.exe running with -d and -p to load a DLL and execute a specified export.
sigmaWindowsmedium2020-10-09Windows Process Creation: PowerShell Obfuscation Executed via Clip.exe and Clipboard
Flags Windows command lines indicating clip.exe clipboard use followed by obfuscated PowerShell invoke behavior.
sigmaWindowshigh2020-10-09Windows Arbitrary File Download via GfxDownloadWrapper.exe URL Argument Execution
Flags GfxDownloadWrapper.exe executions that include http/https URLs for downloading files, excluding a known Intel gameplay API URL.
sigmaWindowsmedium2020-10-09Windows: Detect ftp.exe Executed With -s or /s for Script-Based Command Execution
Flags Windows executions of ftp.exe using -s or /s, indicating potential scripted command abuse.
sigmaWindowsmedium2020-10-09PowerShell Script Obfuscation Triggered by Use of clip.exe and Clipboard Invocation
Flags PowerShell Script Block Logging containing clip.exe/clipboard chaining and clipboard-driven execution markers.
sigmaWindowshigh2020-10-09PowerShell module obfuscation using clip.exe with echo and clipboard invocation
Flags obfuscated PowerShell module scripts that echo “clip” and invoke clipboard-related behavior.
sigmaWindowshigh2020-10-09Windows PowerShell: Detect Suspicious Opsec Artifacts in Script Module Content
Identifies PowerShell module content containing frequent offensive payload string markers associated with poor operational security.
sigmaWindowscritical2020-10-09Windows Service Control Manager Rundll32 Obfuscation via Command-Line Encoded PowerShell
Detects service creation where ImagePath invokes rundll32 (shell32) with command-chain tokens indicative of obfuscated PowerShell.
sigmaWindowshigh2020-10-09Windows System: mshta Launches vbscript:createobject via Service Control Manager (Event ID 7045)
Flags Windows service creation (7045) where ImagePath includes mshta and vbscript:createobject.
sigmaWindowshigh2020-10-09Windows System: Suspicious Clip.exe Execution via Service Control Manager (Event ID 7045)
Alerts on Windows service creation starting clipboard/Clip.exe-related binaries via Service Control Manager ImagePath.
sigmaWindowshigh2020-10-09Windows Security 4697: Obfuscated command uses rundll32 with shell32.dll
Alerts on EventID 4697 service command lines containing rundll32 with shell32.dll/shellexec_rundll and obfuscation-like script fragments.
sigmaWindowshigh2020-10-09Windows Security EID 4697: mshta Used to Run Obfuscated VBScript PowerShell
Detects service creation where the binary path includes mshta plus VBS/automation indicators consistent with script-based obfuscation.
sigmaWindowshigh2020-10-09Windows Security 4697: Obfuscated PowerShell via use of Clip.exe from scripts
Alerts on EID 4697 service installations where the service file name matches Clip/clipboard indicators tied to obfuscated PowerShell.
sigmaWindowshigh2020-10-09Windows regini.exe Execution Leading to Registry Key Changes
Alerts on Windows executions of regini.exe that can import registry changes from text files.
sigmaWindowslow2020-10-08Windows net.exe Unmount Share (/delete) Execution
Alerts on net.exe/net1.exe commands that include "share" and "/delete", indicating share unmount/removal on Windows.
sigmaWindowslow2020-10-08