Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
PowerShell Script Block WinAPI Calls Indicative of Injection or Token Abuse (Windows)
Detects PowerShell ScriptBlocks containing WinAPI function-name combinations consistent with injection and token manipulation.
sigmaWindowshigh2020-10-06Windows UAC Bypass via dism.exe Loading Fake dismcore.dll
Alerts when dism.exe loads a dismcore.dll that is not the expected System32 Dism DLL.
sigmaWindowshigh2020-10-06Windows Time Travel Debugging DLL Loads (ttdrecord/ttdwriter/ttdloader)
Flags Windows image loads of Time Travel Debugging Utility DLLs (tdrecord/tdwriter/tdloader), often abused for stealthy credential dumping.
sigmaWindowshigh2020-10-06Windows file events: Winrm.vbs payload XSL execution artifacts WsmPty.xsl/WsmTxt.xsl outside system folders
Alert on WsmPty.xsl/WsmTxt.xsl files written outside System32 and SysWOW64, consistent with WinRM VBScript misuse.
sigmaWindowsmedium2020-10-06Windows PowerShell Remote Thread Into lsass.exe Suggesting Credential Dumping
Alerts when PowerShell creates a remote thread into lsass.exe, indicating possible credential dumping on Windows.
sigmaWindowshigh2020-10-06PowerShell Script Execution via Windows Service Creation (Service Control Manager)
Flags service creation/start events where the service ImagePath references PowerShell (powershell/pwsh).
sigmaWindowshigh2020-10-06Windows Service Creation of PowerShell/Pwsh Scripts (Security EID 4697)
Alerts on service creation events where the service executable name includes powershell or pwsh.
sigmaWindowshigh2020-10-06Non-privileged reg.exe or PowerShell registry service configuration changes on Windows
Flags non-admin reg.exe or PowerShell activity targeting service registry configuration paths on Windows.
sigmaWindowshigh2020-10-05Windows Print Executable Misuse via print.exe Command-Line
Flags suspicious print.exe invocations using /D and .exe, excluding command lines that explicitly contain print.exe.
sigmaWindowsmedium2020-10-05Windows: Rundll32 LaunchApplication via pcwutl.dll
Flags rundll32.exe using pcwutl.dll to invoke LaunchApplication.
sigmaWindowsmedium2020-10-05Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters
Alerts when Windows process command lines include Hydra -u/-p parameters with USER/PASS placeholders.
sigmaWindowshigh2020-10-05Windows findstr.exe Subfolder and Case-Insensitive Search Flags
Alerts on findstr.exe executions that include both -s (subfolders) and -i (case-insensitive) flags.
sigmaWindowslow2020-10-05Windows: SyncAppvPublishingServer.exe execution via PowerShell script block content
Flags PowerShell script blocks that reference SyncAppvPublishingServer.exe, indicating possible execution via a PowerShell-restricted workflow.
sigmaWindowsmedium2020-10-05Windows SyncAppvPublishingServer Execution Triggering PowerShell Module Context
Alerts when SyncAppvPublishingServer.exe appears in PowerShell module ContextInfo on Windows.
sigmaWindowsmedium2020-10-05Windows Security: Suspicious Remote Logon Using Explicit Credentials via Command-Line Tools
Flags EventID 4648 remote logons initiated by cmd/PowerShell/winrs/wmic/net/reg-style processes using explicit credentials.
sigmaWindowsmedium2020-10-05Windows: Manual persistence attempt using schtasks to run Microsoft Compatibility Appraiser
Alerts when schtasks runs "Microsoft Compatibility Appraiser" via Application Experience, consistent with persistence abuse.
sigmaWindowsmedium2020-09-29Windows service configuration tampering via sc/reg with payload execution paths
Looks for sc/reg command-line activity that updates Windows service ImagePath or FailureCommand to run attacker-controlled payloads.
sigmaWindowsmedium2020-09-29Windows COM Hijack by Registry DelegateExecute Modification (HKCU Classes Folder\shell\open\command)
Flags HKCU DelegateExecute registry changes for COM hijack style persistence under the Folder shell open command.
sigmaWindowshigh2020-09-27Windows VirtualBox Driver Registration or VM Startup via Process Command Line
Alerts on Windows processes whose command lines reference VirtualBox driver registration or VM start/control actions.
sigmaWindowslow2020-09-26Windows NetLogon Secure Channel Connection Allowed for Vulnerable Client
Alerts on Windows NetLogon ETW events indicating an allowed secure channel connection (Event ID 5829).
sigmaWindowshigh2020-09-15