Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
528 rules
Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Alerts on the Windows process/command-line pattern consistent with the Axios npm compromise execution and C2 fetch.
sigmahigh2026-04-01Windows File Creation Indicators Linked to Malicious Axios npm Supply-Chain Components
Flags Windows file creation of wt.exe/system.bat and temp .vbs/.ps1 payloads when created by node.exe or powershell.exe.
sigmahigh2026-04-01Windows System Restore Registry Modification via PowerShell or reg.exe Command Line
Flags PowerShell/reg.exe command lines modifying Windows System Restore registry keys to disable or restrict recovery.
sigmaWindowshigh2026-03-11Detect Email Forwarding/Redirecting via Exchange PowerShell InboxRule Cmdlets on Windows
Alerts when PowerShell script blocks reference Exchange inbox/rule cmdlets and forwarding/redirect parameters.
sigmamedium2026-03-01OpenEDR ssh-shellhost Spawning Cmd or PowerShell With PTY on Windows
Alerts when OpenEDR ssh-shellhost.exe starts cmd.exe or PowerShell with --pty from under ITSMService.exe.
sigmaWindowsmedium2026-02-19Windows PowerShell: New-InboxRule/Set-InboxRule Script Block Activity
Detects PowerShell script content using Exchange cmdlets to create or update inbox rules with message-manipulation actions.
sigmamedium2026-02-10Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
sigmaWindowshigh2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
sigmaWindowshigh2026-01-26Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Alerts when reg.exe or PowerShell modifies User Shell Folders/Shell Folders Startup-related registry values.
sigmaWindowshigh2026-01-05Windows Credential Guard Registry Key Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/Reg.exe commands that add/modify/delete DeviceGuard/LSA registry values tied to Credential Guard.
sigmaWindowshigh2025-12-26Windows Process Creation: Registry Modification to Disable ETW AutoLogger via reg.exe or PowerShell
Flags reg.exe or PowerShell registry changes aimed at disabling WMI AutoLogger EventLog session components.
sigmaWindowshigh2025-12-25Windows Process Command-Line Tampering of AMSI Registry Values via reg.exe or PowerShell
Alerts on reg.exe or PowerShell command lines attempting to add/set AMSI enable registry settings.
sigmaWindowshigh2025-12-25Windows: Suspicious Script/Command Child Processes Spawned by ArcSOC.exe
Alerts when ArcSOC.exe launches cmd/cscript/mshta/powershell/wscript and similar interpreters, indicating potential remote code execution.
sigmaWindowshigh2025-11-25Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.
sigmaWindowshigh2025-11-19Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Flags PowerShell command lines that reference KerberosRequestorSecurityToken and .GetRequest() for suspicious Kerberos ticket requests.
sigmaWindowshigh2025-11-18Windows RDP Enable/Disable via Win32_TerminalServiceSetting WMI Tool Commands
Flags WMIC/PowerShell command lines that reference Win32_TerminalServiceSetting SetAllowTSConnections to change RDP.
sigmaWindowsmedium2025-11-15Windows Process Creation: Suspicious cmd.exe or PowerShell Child of WSUS (wsusservice.exe)
Alerts when WSUS/IIS service processes spawn cmd or PowerShell interpreters, indicating potential exploitation and post-exploitation activity.
sigmahigh2025-10-31Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Flags Windows process trees where GoAnywhere Tomcat spawns suspicious cmd/PowerShell command lines consistent with exploitation activity.
sigmahigh2025-10-07Windows: Suspicious Velociraptor Child Process Execution Indicators
Alerts when Velociraptor.exe spawns specific child processes tied to tunneling, msiexec web installs, or PowerShell download commands.
sigmaWindowshigh2025-08-29Windows PowerShell Uninstall-WindowsFeature/Remove-WindowsFeature Removing Windows-Defender GUI
Detects PowerShell uninstall/removal commands targeting the Windows-Defender GUI feature.
sigmaWindowshigh2025-08-22