Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Reported BINDCLOAK Encrypted Payload File Event
Detects file telemetry for the exact encrypted payload filename shown in the attack-flow image. It covers the file IOC, not the decryption or reflective loading behavior.
sigmaWindowsPaidhigh2026-07-30WordPress wp2shell PoC User-Agent HTTP Requests
Alerts on web requests with User-Agent exactly equal to "wp2shell", matching wp2shell PoC behavior.
sigmahigh2026-07-19Windows Process: SystemSettingsAdminFlows.exe Used to Disable Windows Defender
Alerts when SystemSettingsAdminFlows.exe is launched with command-line arguments consistent with disabling Windows Defender.
sigmaWindowshigh2026-07-01Linux Process Execution from /dev/shm Shared Memory Directory
Alerts on Linux processes executing binaries from /dev/shm, a common in-memory staging location.
sigmaLinuxhigh2026-06-20Windows Process Creation: curl.exe Using NTLM with Empty Username (-u :)
Alerts when curl is run on Windows with --ntlm and empty -u : credentials, a pattern that may leak the current user's NTLMv2 response.
sigmaWindowshigh2026-06-04Windows: Detect LSASS crashes caused by netlogon.dll stack buffer overrun (STATUS_STACK_BUFFER_OVERRUN)
Alerts on lsass.exe crashes blamed on netlogon.dll with STATUS_STACK_BUFFER_OVERRUN (0xc0000409) in Windows Application Error (EventID 1000).
sigmahigh2026-06-02Windows Execution of tanstack_runner.js via bun.exe
Flags bun.exe launching a script via "run tanstack_runner.js" on Windows.
sigmahigh2026-05-12Linux process execution indicators for TanStack preinstall supply-chain payloads
Flags Linux processes running a Bun-based TanStack runner (and related Python pyz payload execution) indicative of supply-chain compromise.
sigmahigh2026-05-12Linux: Detect modprobe-based authencesn crypto module auto-load via kmod
Flags modprobe/kmod processes loading the authencesn crypto module when command lines contain "crypto-authencesn(".
sigmahigh2026-05-09Linux auditd: Detect AF_ALG socket() syscall (address family 38) for crypto API abuse
Flags AF_ALG (38) socket() creations from Linux auditd while filtering common legitimate crypt/VPN tools.
sigmahigh2026-04-30Windows Print.EXE Sensitive File Dump for Credential Access
Alerts when Print.EXE is executed with arguments targeting ntds.dit, SAM, SECURITY, and SYSTEM files for credential access.
sigmaWindowshigh2026-04-28Windows PUA: MemProcFS memory dump mounting via -device
Detects MemProcFS.exe execution with -device on Windows, consistent with mounting memory dumps for potential credential access.
sigmaWindowshigh2026-04-27Windows HackTool Indicators: NetExec (nxc.exe) PyInstaller Extraction Artifacts
Flags Windows file creation under Temp\_MEI* where NetExec nxc data files are dropped, indicating likely NetExec execution.
sigmaWindowshigh2026-04-08Windows Process Tree for Axios npm Supply-Chain RAT Droppers (cscript, curl, PowerShell)
Alerts on the Windows process/command-line pattern consistent with the Axios npm compromise execution and C2 fetch.
sigmahigh2026-04-01macOS: Detect Axios malicious npm execution chain using osascript, curl download, and cleanup
Flags macOS command-line patterns showing osascript execution plus npm package download and staged file cleanup.
sigmahigh2026-04-01Linux process chain for Axios NPM compromise: curl download with nohup and python3
Flags Linux executions where curl downloads /tmp/ld.py and the payload is run via nohup python3 from an Axios-related node process.
sigmahigh2026-04-01DNS queries to known malicious C2 domains from axios/plain-crypto-js npm compromise indicators
Alerts on DNS queries to known malicious C2 domains tied to an Axios npm supply-chain compromise.
sigmahigh2026-04-01Windows File Creation Indicators Linked to Malicious Axios npm Supply-Chain Components
Flags Windows file creation of wt.exe/system.bat and temp .vbs/.ps1 payloads when created by node.exe or powershell.exe.
sigmahigh2026-04-01macOS: Axios NPM compromise file creation via curl and node indicators
Alerts on macOS file events matching curl and node staging paths linked to an Axios npm compromise pattern.
sigmahigh2026-04-01Linux file creation via curl to /tmp/ld.py (Axios NPM compromise indicators)
Alerts on Linux file creation of /tmp/ld.py by a /curl process, consistent with automated payload staging.
sigmahigh2026-04-01