Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows desktopimgdownldr Suspicious URL and Registry Modification via Command Line
Flags desktopimgdownldr command lines indicating potential external file download or personalization registry deletion.
sigmaWindowshigh2020-07-03Windows curl.exe Suspicious Download to Local File Paths
Flags curl.exe executions on Windows that appear to download to local files in suspicious directories with risky file extensions.
sigmaWindowshigh2020-07-03Windows Desktop Image Downloader Targeting Lock Screen Images with Suspicious File Types
Alerts on desktopimgdownldr-style lock screen image target writes to non-system paths with suspicious filename characteristics.
sigmaWindowshigh2020-07-03Windows Registry Printer Driver Installations with Empty Manufacturer Field
Alerts on Windows registry printer driver environment updates where Manufacturer is set to empty.
sigmaWindowshigh2020-07-01Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution
Alerts on AppLocker event IDs showing blocked execution of apps, scripts, DLLs, MSI, or packaged apps.
sigmaWindowsmedium2020-06-28Windows Security Log: Denied Remote Desktop Logon (Event ID 4825)
Flags Windows denied RDP connection attempts from users lacking permission to log on remotely (Event ID 4825).
sigmaWindowsmedium2020-06-27Windows Registry Event Triggered by RedMimicry Winnti Playbook (HTMLHelp\data)
Alerts on Windows registry events targeting HKLM\SOFTWARE\Microsoft\HTMLHelp\data associated with the RedMimicry Winnti playbook.
sigmaWindowshigh2020-06-24Windows process execution matching Winnti RedMimicry playbook (rundll32/cmd with temp batch and gthread/sigcmm DLLs)
Flags rundll32.exe/cmd.exe launches with Winnti-specific DLL and temp batch indicators.
sigmaWindowshigh2020-06-24Suspicious WSMAN COM Provider Usage Without PowerShell Host (Windows)
Alerts on WSMAN COM provider activity where the host application is not PowerShell.exe in PowerShell Classic logs.
sigmaWindowsmedium2020-06-24Windows File Drops Matching Winnti Dropper Artifacts (gthread/sigcmm DLLs, tmp.bat)
Detects Windows file drops of specific DLLs and a Windows Temp batch filename pattern associated with a Winnti dropper scenario.
sigmaWindowshigh2020-06-24Windows Process Creation: Detect reg.exe Add Control Panel CPL Items
Alerts on reg.exe adding Control Panel CPL items via CurrentVersion\Control Panel\CPLs, a common vector for stealthy execution/persistence.
sigmaWindowshigh2020-06-22Windows Process Creation: IE Security Registry Values Disabled via Command Line
Alerts on Windows command lines that set IE hardening-related registry values to disable security features.
sigmaWindowshigh2020-06-19Windows Process Creation: Possible Path Traversal in cmd.exe Command Line
Alerts on Windows cmd.exe executions with "../.." path traversal indicators in parent/child command lines.
sigmaWindowshigh2020-06-11Windows Pcap Driver Installation via EID 4697 ServiceFileName
Flags Windows driver install events (Security 4697) where the service file name matches known Pcap-related driver keywords.
sigmaWindowsmedium2020-06-10Windows file indicators for Octopus Scanner malware artifacts
Alerts on Windows file activity for Octopus Scanner-related filenames (Cache134.dat, ExplorerSync.db) in AppData.
sigmaWindowshigh2020-06-09Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Alerts on Windows consent-store registry entries showing webcam/microphone access tied to Temp or public user paths.
sigmaWindowshigh2020-06-07Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore
Identifies Windows processes interacting with non-packaged app consent entries for microphone and webcam access.
sigmaWindowsmedium2020-06-07Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags
Alerts on Sysmon registry sets that set .NET ETWEnabled/COMPlus ETW flags to 0, impairing ETW-based telemetry.
sigmaWindowshigh2020-06-05Windows Registry ETW Logging Disabled for .NET via Security Event 4657
Alerts when .NET ETW logging is disabled via registry changes (ETWEnabled or COMPlus ETW settings) using Event ID 4657.
sigmaWindowshigh2020-06-05Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Identifies Windows PowerShell command lines commonly used by Covenant launchers, including hidden/encoded execution patterns.
sigmaWindowshigh2020-06-04