Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows: Renamed Sysinternals DebugView Process Execution
Flags Windows executions labeled as Sysinternals DebugView when the image is not the original Dbgview.exe.
sigmaWindowshigh2020-05-28Windows: New Executables Named After System Processes in Non-System Paths
Alerts on creation of executables named like common system processes in unexpected Windows directories.
sigmaWindowsmedium2020-05-26Windows netsh.exe Whitelists Allowed Program from Suspicious Path in Firewall
Flags netsh.exe firewall allow rules that whitelist a program located in suspicious Windows filesystem paths.
sigmaWindowshigh2020-05-25Windows RDP Port 3389 Allowed via netsh.exe Firewall Rule Creation
Flags netsh.exe commands that add firewall rules allowing TCP port 3389 (RDP).
sigmaWindowshigh2020-05-23Windows Registry: Office VBAWarning Disabled (VBAWarnings set to 1)
Alerts on Security\VBAWarnings being set to DWORD 0x00000001, enabling all Office VBA macros.
sigmaWindowshigh2020-05-22Windows Registry Set AccessVBOM DWORD=1 Disables Access Security for Access VBA
Alerts on Windows registry changes setting Security\AccessVBOM to DWORD 1, disabling VBA trust access to bypass Office warnings.
sigmaWindowshigh2020-05-22Windows: CrackMapExec PowerShell obfuscation via join/split static patterns
Flags Windows PowerShell executions with command-line obfuscation strings associated with CrackMapExec behavior.
sigmaWindowshigh2020-05-22Windows NTLM Logon to TERMSRV on Non-Domain Hosts
Alerts on Windows NTLM events tied to TERMSRV targets that may be non-domain hosts, suggesting potential RDP access.
sigmaWindowsmedium2020-05-22Windows Network Connections Initiated by Notepad.exe
Alerts when notepad.exe initiates an outbound network connection, excluding typical printing traffic on port 9100.
sigmaWindowshigh2020-05-14Windows: Detect rar.exe Archive Creation Using Password or Compression Options
Alerts on rar.exe command lines that include both password protection (-hp) and additional compression/archive flags.
sigmaWindowshigh2020-05-12Windows: Advanced IP Scanner (PUA) Execution via Process Creation
Identifies Windows processes running Advanced IP Scanner using filename/description and command-line arguments.
sigmaWindowsmedium2020-05-12Advanced IP Scanner Execution from Temp Folder via Windows File Events
Flags file activity targeting Advanced IP Scanner 2 under a Windows user Temp directory.
sigmaWindowsmedium2020-05-12Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.
sigmaWindowshigh2020-05-11Windows Security Log: Metasploit SMB NTLM Logon (4624/4625, 4776)
Detects Metasploit-linked NTLM SMB authentication activity using Windows 4624/4625 and 4776 with 16-char workstation names.
sigmaWindowshigh2020-05-06Windows Failed Logon (Event ID 4625) From Non-Private Public IP
Alerts on Windows failed logons (4625) originating from IPs outside private/local ranges.
sigmaWindowsmedium2020-05-06Windows Fax Service ualapi.dll Side-Loading via fxssvc.exe
Flags fxssvc.exe loading ualapi.dll from unexpected paths, indicating potential DLL side-loading for privilege escalation.
sigmaWindowshigh2020-05-04Windows AppCompatFlags Store New Application Registry Entries
Alerts on new writes to the AppCompat Compatibility Assistant store registry path, indicating first-time application behavior.
sigmaWindowsinformational2020-05-02Windows Registry Deletion of Shell Open Command COM Hijacking Key Paths
Flags registry deletions of \shell\open\command paths that may indicate removal of COM hijacking execution entries.
sigmaWindowsmedium2020-05-02Windows sdclt.exe Spawned with High Integrity (Possible UAC Bypass)
Alerts on sdclt.exe launching as High integrity, indicating possible elevated execution consistent with UAC bypass attempts.
sigmaWindowsmedium2020-05-02Windows Process Creation: .NET ETW Logging Environment Variables Set via Command Line
Flags process command lines setting COMPlus_ETWEnabled/COMPlus_ETWFlags, potentially impairing ETW logging for .NET.
sigmaWindowshigh2020-05-02