Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
WordPress wp2shell Plugin Webshell Access via wp-content/plugins URL Path
Alert on HTTP requests targeting the wp2shell WordPress plugin path used for webshell execution/persistence.
sigmacritical2026-07-19Antivirus Remote Access Tool Signature Matches Known RAT Names
Alerts on antivirus detections referencing multiple known RAT family signature names in the event signature field.
sigmacritical2026-06-15Antivirus signatures matching APT malware naming patterns
Flags Antivirus alerts when malware signatures reference APT-style naming patterns and family name substrings.
sigmacritical2026-06-15Windows Defender windefend Event 1119 flags RedSun TieringEngineService.exe EICAR test file
Alerts on WinDefend 1119 remediation failures involving TieringEngineService.exe marked with EICAR content or triggered by RedSun.exe.
sigmacritical2026-04-17Windows Named Pipe Created with Name "REDSUN"
Flags creation of the named pipe \REDSUN on Windows, consistent with RedSun-style IPC used during exploitation.
sigmacritical2026-04-17Windows File Creation: TieringEngineService.exe in RS- prefixed Temp Directory
Detects creation of TieringEngineService.exe under an RS-{GUID}-prefixed directory in %TEMP% on Windows.
sigmacritical2026-04-17Windows File Creation in SharePoint Web Server Extensions Suggesting ToolShell Drop
Alerts on Windows file creations within SharePoint Web Server Extensions that match suspicious spinstall/debug artifacts linked to CVE-2025-53770.
sigmacritical2025-07-21Bitbucket Audit: Unauthorized Full Data Export Triggered (Data Pipeline)
Flags Bitbucket audit events indicating an unauthorized user attempted a full data export.
sigmacritical2024-02-25Bitbucket Audit: Unauthorized Access to a Resource
Flags Bitbucket audit events reporting unauthorized access attempts to a resource.
sigmacritical2024-02-25Webserver Path Scan for ScreenConnect SetupWizard Authentication Bypass (CVE-2024-1709)
Alerts on web requests to '/SetupWizard.aspx/' that match exploitation patterns for ScreenConnect authentication bypass CVE-2024-1709.
sigmacritical2024-02-20Windows Security Event 4698 Scheduled Task Creation for TeamCity UI
Flags Windows scheduled task creation events where the task name is TeamCity Settings UI and content contains a specific marker.
sigmacritical2023-10-24Proxy HTTP GET Pattern Matching /MSHTML_C7/ with IPv4 Query Parameters
Alerts on proxy HTTP GET requests to /MSHTML_C7/ with an IPv4-like query parameter pattern.
sigmacritical2023-07-12Linux Process Execution of BarracudaMailService and Resize Utility Binaries
Alerts on Linux process creation for executables ending with three specific names linked to SEASPY deployment.
sigmacritical2023-06-16Windows Rundll32 Execution via Suspicious DLL Path Without .dll Extension
Alerts when rundll32.exe is started from suspicious parent scripts with a DLL-like path missing the .dll extension.
sigmacritical2023-05-24Windows Qakbot-associated Rundll32 execution via suspicious parent process and export strings
Flags rundll32.exe executions tied to Qakbot-style export strings when launched by script/cmd utilities.
sigmacritical2023-05-24Proxy HTTP GET to api.telegram.org with chat_id and text com/ (Small Sieve C2 behavior)
Alerts on proxy HTTP GET requests to api.telegram.org containing a specific chat_id and com/ prefix consistent with C2 behavior.
sigmacritical2023-05-19Windows Service Creation for Backdoor Persistence via GoogleUpdate (Event ID 7045)
Flags creation of a "GoogleUpdate" Windows service with rundll32/FileProtocolHandler image path pointing to ProgramData persistence.
sigmacritical2023-05-15Windows Service Creation for WerFaultSvc Using C:\Windows\WinSxS\WerFault.exe
Alerts on Windows service creation of WerFaultSvc pointing to C:\Windows\WinSxS\...\WerFault.exe.
sigmacritical2023-05-10Windows File Indicator: SNAKE Malware Kernel Driver Target File Comadmin.dat
Alerts on Windows file events involving C:\Windows\System32\Com\Comadmin.dat, an indicator tied to SNAKE kernel driver activity.
sigmacritical2023-05-10Windows: Suspicious child processes spawned from Veeam SQL Server service
Alerts on suspicious cmd/PowerShell/LOLBin and recon utilities spawned by the Veeam SQL service (sqlservr.exe with VEEAMSQL).
sigmaWindowscritical2023-05-04