Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
2300 rules
Windows Process: SystemSettingsAdminFlows.exe Used to Disable Windows Defender
Alerts when SystemSettingsAdminFlows.exe is launched with command-line arguments consistent with disabling Windows Defender.
sigmaWindowshigh2026-07-01Failed WMI NTEventLogFile ClearEventLog attempts (Windows WMI Event 5858)
Alerts on WMI errors (Event 5858) tied to attempted NTEventLogFile ClearEventLog calls on Windows.
sigmaWindowsmedium2026-07-01Windows Process Creation: curl.exe Using NTLM with Empty Username (-u :)
Alerts when curl is run on Windows with --ntlm and empty -u : credentials, a pattern that may leak the current user's NTLMv2 response.
sigmaWindowshigh2026-06-04Windows Print.EXE Sensitive File Dump for Credential Access
Alerts when Print.EXE is executed with arguments targeting ntds.dit, SAM, SECURITY, and SYSTEM files for credential access.
sigmaWindowshigh2026-04-28Windows: WMIC service ChangeStartMode sets Manual or Disabled startup type
Detects wmic.exe commands changing a Windows service startup type to Manual or Disabled via ChangeStartMode.
sigmaWindowsmedium2026-04-27Windows SFTP.exe Indirect Command Execution via ProxyCommand
Flags SFTP.exe executions that include ProxyCommand=, indicating potential indirect command execution.
sigmaWindowsmedium2026-04-27Windows PUA: MemProcFS memory dump mounting via -device
Detects MemProcFS.exe execution with -device on Windows, consistent with mounting memory dumps for potential credential access.
sigmaWindowshigh2026-04-27Windows HackTool Indicators: NetExec (nxc.exe) PyInstaller Extraction Artifacts
Flags Windows file creation under Temp\_MEI* where NetExec nxc data files are dropped, indicating likely NetExec execution.
sigmaWindowshigh2026-04-08Windows: Detect NetExec (nxc.exe) Process Execution with Network Service Commands
Flags Windows execution of NetExec (nxc.exe) when command lines include SMB/RDP/SSH/WinRM/WMI and other protocol keywords.
sigmaWindowshigh2026-03-29Windows Process Creation: curl Uploads to File-Sharing Domains
Detects curl commands on Windows uploading files to common file sharing/upload domains.
sigmaWindowshigh2026-03-29Windows AppLocker Audit-Mode Events Indicate Files Would Have Been Blocked
Alerts on AppLocker audit-only reports that specific apps would have been blocked if enforcement rules were enabled.
sigmaWindowsmedium2026-03-26Windows System Restore Registry Modification via PowerShell or reg.exe Command Line
Flags PowerShell/reg.exe command lines modifying Windows System Restore registry keys to disable or restrict recovery.
sigmaWindowshigh2026-03-11Windows Process Creation: Python One-Liners Decoding Base64 via Command Line
Alerts on Windows Python command-line one-liners that import base64 and call decode functions.
sigmaWindowshigh2026-03-09OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Alerts when OpenEDR ssh-shellhost.exe starts cmd.exe or PowerShell with --pty from under ITSMService.exe.
sigmaWindowsmedium2026-02-19Suspicious File Creation by OpenEDR ITSMService on Windows
Alerts on Windows file creations by OpenEDR ITSMService.exe when the target ends with common executable or script/archive extensions.
sigmaWindowsmedium2026-02-19Windows Process Creation: node.exe Running npx skills add New Agent Skills
Alerts when node.exe invokes the npx skills add flow to install new agent skills on Windows.
sigmaWindowsmedium2026-02-03Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Alerts when Notepad++ gup.exe spawns command/scripting or utility processes using suspicious tool keywords on Windows.
sigmaWindowshigh2026-02-03Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations
Alerts on file creations by Notepad++ updater gup.exe when the destination path is uncommon or not in allowed locations.
sigmaWindowshigh2026-02-03Windows DNS Monitoring: gup.exe Queries to Uncommon Domains
Alerts when Notepad++ gup.exe generates DNS queries to domains outside the approved set.
sigmaWindowsmedium2026-02-02Windows Vulnerable Driver Blocklist Disabled via Registry DWORD Setting
Flags registry changes that disable Windows Vulnerable Driver Blocklist (VulnerableDriverBlocklistEnable = 0).
sigmaWindowshigh2026-01-26