Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process Execution of .SettingContent-ms Command Line
Flags Windows processes whose command lines reference .SettingContent-ms, a potential trigger for setting-based execution.
sigmaWindowsmedium2020-03-13Windows: Alert on Uncommon Child Process Executed from Appvlp.exe
Alerts on unusual child processes created by Appvlp.EXE on Windows, indicating potential command execution abuse.
sigmaWindowsmedium2020-03-13Windows: Suspicious Execution of CSharp Interactive Console via PowerShell
Alerts when PowerShell launches csi.exe, indicating possible interactive .NET code execution.
sigmaWindowshigh2020-03-08Windows MMC20 Lateral Movement via MMC.exe -Embedding spawned by svchost.exe
Alerts when svchost.exe launches mmc.exe with “-Embedding”, indicating potential MMC20 COM-based lateral movement.
sigmaWindowshigh2020-03-04Windows Registry: TrustRecords key modification indicating macro-based initial access
Flags Windows registry writes to Security\Trusted Documents\TrustRecords, a signal consistent with macro-enabled initial access.
sigmaWindowsmedium2020-02-19Windows: Office Application Loads VBE VBA DLLs via Image Load Events
Flags Office apps loading VBA-related VBE DLLs, a strong indicator of VBA macro execution.
sigmaWindowshigh2020-02-19Windows Office Apps Loading .NET GAC MSIL DLLs via Image Load Events
Alerts when an Office app loads a .NET DLL from the GAC_MSIL directory.
sigmaWindowshigh2020-02-19Windows: CLR DLL Loaded by Office Applications
Alerts when Excel, Word, Outlook, PowerPoint, Publisher, or OneNote loads clr.dll on Windows.
sigmaWindowsmedium2020-02-19Windows Office Apps Loading .NET Assembly DLLs from C:\Windows\assembly
Alerts when Office applications load DLLs from C:\Windows\assembly\ via image load events.
sigmaWindowsmedium2020-02-19Windows Process Memory Dump via comsvcs.dll using rundll32
Alert on rundll32 loading comsvcs.dll with arguments consistent with a full process memory dump.
sigmaWindowshigh2020-02-18Windows Process Creation: Sticky Keys Backdoor via sethc.exe Replacement
Flags forced replacement of C:\Windows\System32\sethc.exe with cmd.exe consistent with a Sticky Keys backdoor.
sigmaWindowscritical2020-02-18Windows: Flag SettingSyncHost.exe used to execute RoamDiag.cmd from cmd.exe
Flags non-System32/SysWOW64 processes spawned by SettingSyncHost.exe running RoamDiag.cmd via cmd.exe /c -outputpath.
sigmaWindowshigh2020-02-05Windows: Dumpert Process Dumper Execution via Dumpert.dll or Known MD5
Detects Dumpert execution on Windows via known hash and command line reference to Dumpert.dll for lsass memory dumping.
sigmaWindowscritical2020-02-04Windows File Creation of Dumpert Default Dump (dumpert.dmp)
Alerts on creation of Dumpert’s default "dumpert.dmp" dump file on Windows.
sigmaWindowscritical2020-02-04PowerShell CommandLine Uses FromBase64String to Decode Base64 Content (Windows)
Detects PowerShell process creation where the command line includes ::FromBase64String(, indicating Base64 decoding.
sigmaWindowshigh2020-01-29Windows renamed dctask64.exe execution via known IMPHASH values
Flags Windows process creations where a renamed dctask64.exe execution matches known IMPHASH values.
sigmaWindowshigh2020-01-28Windows Process Creation: Detect dctask64.exe with Endpoint Central Execution/Injection Flags
Alerts on Windows execution of ManageEngine Endpoint Central dctask64.exe with specific hash and suspicious command-line indicators.
sigmaWindowshigh2020-01-28Windows MSTSC Shadowing CommandLine Using shadow:
Flags Windows processes launching MSTSC with noconsentprompt and shadow: parameters consistent with RDP session shadowing.
sigmaWindowshigh2020-01-24Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Alerts on Windows Audit-CVE EventID 1 entries from Microsoft-Windows-Audit-CVE provider indicating CveEventWrite activity.
sigmaWindowscritical2020-01-15Windows Process Command Lines Using System32/SysWow64 Tasks Folder
Alerts on process command lines referencing the writable System32/SysWow64 Tasks folders with common file staging/copy primitives.
sigmaWindowshigh2020-01-13