Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Dumping via sqldumper.exe with 0x0110 Command-Line Flags
Alerts on sqldumper.exe executions with command-line dump parameters indicative of process dumping.
sigmaWindowsmedium2020-10-08Windows: Code Execution via Pester.bat Using PowerShell Help or cmd.exe
Flags Windows process executions that invoke Pester-related help/commands via PowerShell or cmd, consistent with Pester.bat usage.
sigmaWindowsmedium2020-10-08Windows Process Execution: Obfuscated PowerShell Invocation Using mshta with VBScript CreateObject
Flags Windows process command lines containing an obfuscated PowerShell+MSHTA VBScript execution pattern.
sigmaWindowshigh2020-10-08PowerShell share removal via Remove-SmbShare or Remove-FileShare on Windows
Flags PowerShell commands that remove SMB or file shares through Remove-SmbShare/Remove-FileShare.
sigmaWindowsmedium2020-10-08PowerShell ScriptBlock Obfuscation via MSHTA VBScript CreateObject Execution
Alerts on PowerShell script blocks containing mshta and VBScript createobject/.run/window.close patterns consistent with obfuscated execution.
sigmaWindowshigh2020-10-08PowerShell Module: Obfuscated MSHTA Invocation via VBS CreateObject
Alerts when PowerShell module payload text includes an obfuscated MSHTA/VBScript invocation sequence.
sigmaWindowshigh2020-10-08UAC Bypass Using wsreset.exe Registry Command Path (Windows)
Identifies registry TargetObject values associated with a wsreset-style UAC bypass execution command path on Windows.
sigmaWindowshigh2020-10-07Xwizard.EXE COM Execution with RunWizard and GUID Argument (Windows)
Alerts when Xwizard.EXE runs with RunWizard plus a GUID-like argument on Windows, consistent with COM execution usage.
sigmaWindowsmedium2020-10-07Windows: Remote code execution via winrm.vbs using cscript and wmicimv2/Win32_ Create
Alerts on cscript.exe executions referencing winrm and wmicimv2/Win32_ Create with -r:http, consistent with remote code execution via winrm.vbs.
sigmaWindowsmedium2020-10-07Rundll32 Executes Setupapi.dll InstallHinfSection via Runonce.exe
Alerts when rundll32 passes setupapi.dll::InstallHinfSection arguments that result in launching runonce.exe.
sigmaWindowsmedium2020-10-07Windows DLL execution via register-cimprovider.exe with -path dll
Alerts on register-cimprovider.exe launching with -path pointing to a DLL.
sigmaWindowsmedium2020-10-07Windows regedit.exe Imports Registry Keys From .reg File
Detects regedit.exe command lines importing registry keys from .reg files on Windows.
sigmaWindowsmedium2020-10-07Windows Registry Key Export via regedit.exe (-E) to File
Flags regedit.exe registry exports to files using the -E option, indicating potential discovery or exfiltration prep.
sigmaWindowslow2020-10-07Windows Visual Basic vbc.exe Compiles to .obj via cvtres.exe Resource Converter
Alerts when vbc.exe spawns cvtres.exe during Windows VB command-line compilation activity.
sigmaWindowshigh2020-10-07Windows: Process CallTrace using EditionUpgradeManager COM interface DLL
Alerts on process access events with call traces referencing editionupgrademanagerobj.dll via the EditionUpgradeManager COM interface.
sigmaWindowsmedium2020-10-07Windows regedit.exe exports a registry key into an alternate data stream
Flags regedit.exe executions where the process image ends with '\regedit.exe', consistent with exporting Registry data to an alternate data stream.
sigmaWindowshigh2020-10-07PowerShell Service Persistence via Registry ImagePath on Windows
Flags Windows registry service ImagePath entries that reference PowerShell (powershell/pwsh).
sigmaWindowshigh2020-10-06Windows: Winrm.vbs AWL bypass using attacker WsmPty.xsl/WsmTxt.xsl
Detects WinRM vbs execution with suspicious XSL formatting arguments, especially when the binary is outside System32/SysWOW64.
sigmaWindowsmedium2020-10-06Windows: VBoxDrvInst.exe Invoked with driver/executeinf Parameters
Flags VBoxDrvInst.exe launched with parameters indicative of INF processing (driver/executeinf).
sigmaWindowsmedium2020-10-06Windows: Time Travel Debugging Utility (tttracer.exe) Process Execution
Alerts when tttracer.exe is the parent process of a spawned process on Windows.
sigmaWindowshigh2020-10-06