Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Defender Windefend AMSI Detection (Event ID 1116)
Flags Windows Defender AMSI detections via windefend Event ID 1116 with SourceName set to AMSI.
sigmaWindowshigh2020-09-14Windows Registry Set: .NET COR/CORECLR Profiling Environment Variables Enabled
Alerts on registry writes enabling .NET CLR/CORECLR profiling variables like COR_ENABLE_PROFILING and COR_PROFILER.
sigmaWindowsmedium2020-09-10Windows Process Creation: MpCmdRun.EXE Used to Download Files via DownloadFile url
Alerts when MpCmdRun.exe is executed with DownloadFile and url, indicating Defender utility file download behavior.
sigmaWindowshigh2020-09-04WMI scrcons.exe Loading Script and WMI DLLs via Image Load (Windows)
Alerts when scrcons.exe loads vbscript/wbem/WMI script DLLs, suggesting WMI ActiveScriptEventConsumer activity.
sigmaWindowsmedium2020-09-02Windows Process Creation: Mouse Lock Execution with “Misc314” Indicator
Alerts on Windows executions of Mouse Lock where Company includes “Misc314” and CommandLine contains “Mouse Lock_”.
sigmaWindowsmedium2020-08-13Windows Defender windefend Event 1013: Malware detection history deletion
Alerts when Windows Defender deletes its malware/PUA detection history via windefend Event ID 1013.
sigmaWindowsinformational2020-08-13Windows Security Event 5145: SMB Write Access to Admin Share (C$)
Flags non-machine accounts writing via SMB to the C$ administrative share using Security EventID 5145.
sigmaWindowshigh2020-08-06Windows windefend Event ID 5012: Windows Defender virus scanning disabled
Flags when Windows Defender disables virus scanning via windefend Event ID 5012.
sigmaWindowshigh2020-07-28Windows windefend: Windows Defender threat detection and mitigation events
Alerts on windefend events indicating Windows Defender malware detection and potential remediation activity.
sigmaWindowshigh2020-07-28Windows windefend EventID 5001: Windows Defender real-time protection disabled
Flags windefend Event ID 5001 indicating Windows Defender real-time protection was disabled.
sigmaWindowshigh2020-07-28Windows windefend: Microsoft Defender malware and PUA scanning disabled (Event ID 5010)
Flags Windows Defender disabling malware and PUA scanning using Windefend Event ID 5010.
sigmaWindowshigh2020-07-28Windows Defender antimalware grace period expired (Event ID 5101)
Alerts when Windows Defender signals its antimalware grace period expired via windefend Event ID 5101.
sigmaWindowshigh2020-07-28Windows Service Control Manager: Windows Defender Threat Protection Disabled
Flags Service Control Manager events where the Windows Defender Threat Protection (Defender Antivirus) service is stopped.
sigmaWindowsmedium2020-07-28Windows webserver-spawned recon commands probing scripting tool help (perl/python/wget)
Flags webserver child processes running perl/python/python3/wget help commands to probe available tooling on the host.
sigmaWindowshigh2020-07-22Windows DLL Load Indicates Potential Azure Browser SSO OAuth Token Request Abuse
Alerts on MicrosoftAccountTokenProvider.dll loads on Windows, with process-based exclusions, as a signal for potential Azure Browser SSO token activity.
sigmaWindowslow2020-07-15Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
sigmaWindowshigh2020-07-14Windows Sysmon Operational Channel Reference Deleted via Security Event
Detects Security log events showing Sysmon Operational channel being disabled via channel reference deletion-like changes.
sigmaWindowshigh2020-07-14Windows PowerShell Command Lines Containing [char]0x or (WCHAR)0x Obfuscation Syntax
Identifies PowerShell execution command lines using suspicious [char]0x or (WCHAR)0x encoding patterns.
sigmaWindowshigh2020-07-09Windows Process Execution of DIT Snapshot Viewer (ditsnap.exe)
Alerts on execution of the DIT snapshot viewer tool ditsnap.exe on Windows.
sigmaWindowshigh2020-07-04Windows Process Execution: Copy From System Directories to Other Locations
Detects cmd.exe, PowerShell, and copy utilities copying files from System32/SysWOW64/WinSxS to other locations on disk.
sigmaWindowsmedium2020-07-03