Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Masquerading as svchost.exe via Binary Name and Location
Alerts on svchost.exe-named processes launched from non-standard paths with OriginalFileName svchost.exe.
sigmaWindowshigh2024-08-07Windows DLL Side-Loading: OleView loading aclui.dll
Alerts on OleView.exe loading aclui.dll on Windows, excluding common benign paths to highlight potential DLL side-loading.
sigmahigh2024-07-31Windows Security: Changes to "ESX Admins" Domain Group Membership
Alerts on domain group management events involving the "ESX Admins" group name, which may grant privileged access.
sigmahigh2024-07-30Windows Process Creation: net.exe or PowerShell creating AD group "ESX Admins"
Alerts on net.exe or PowerShell attempts to create a domain group named "ESX Admins" via AD/command-line parameters.
sigmahigh2024-07-29Windows COM CLSID Hijacking via Registry Default InprocServer32/LocalServer32 Modification
Detects registry changes to COM CLSID Default InprocServer32/LocalServer32 values that point to suspicious locations.
sigmaWindowshigh2024-07-16Windows Registry Tampering: DsrmAdminLogonBehavior Value Changes (DSRM)
Alerts when DsrmAdminLogonBehavior registry value is changed on Windows, except the default DWORD 0x00000000.
sigmaWindowshigh2024-07-11AWS CloudTrail SSM SendCommand Successful Execution for Instance
Identifies successful AWS SSM SendCommand executions recorded in CloudTrail.
sigmaCloudhigh2024-07-11AWS CloudTrail: Instance Profile Role Assumed Actions Outside SSM RegisterManagedInstance
Identifies CloudTrail activity from assumed-role instance identities when it is not part of SSM RegisterManagedInstance.
sigmaCloudhigh2024-07-11Windows: Detect regedit.exe creating a PDF file
Alerts when RegEdit.exe creates a .pdf file on Windows.
sigmaWindowshigh2024-07-08Windows Registry: DisableHypervisorEnforcedPagingTranslation Set to 1
Alerts when Windows disables Hypervisor Enforced Paging Translation by setting DisableHypervisorEnforcedPagingTranslation to 1.
sigmaWindowshigh2024-07-05Windows Security Event 4698: Kapeka-like Scheduled Task Creation
Flags suspicious Kapeka-like scheduled task creation via Event 4698 using TaskContent paths, rundll32/.wll command markers, and OneDrive/Sens Api task names.
sigmahigh2024-07-03Windows Registry Run Key Autorun Entries Targeting Kapeka Backdoor
Flags Windows Run key registry changes whose data matches a Kapeka-style rundll32 .wll (#1) autorun entry.
sigmahigh2024-07-03Kapeka backdoor execution via rundll32.exe with export ordinal #1 and -d on Windows
Flags rundll32.exe command lines launching a Kapeka payload from ProgramData/AppData Local using export ordinal #1 with "-d".
sigmahigh2024-07-03Windows Kapeka Backdoor Persistence via schtasks ONSTART or Run Registry Autorun
Flags Windows persistence creation for Kapeka using schtasks (ONSTART) or Run registry entries plus rundll32 ordinal-based execution.
sigmahigh2024-07-03Windows: Kapeka backdoor DLL (.wll) loaded via rundll32.exe
Flags rundll32.exe loading a suspicious .wll backdoor from ProgramData or AppData\Local.
sigmahigh2024-07-03Windows file drop: Kapeka-style decrypted backdoor indicators in AppData with .wll naming
Alerts on suspicious Kapeka backdoor file drops in Windows AppData/Common AppData using .wll naming patterns.
sigmahigh2024-07-03Windows Process Creation: RemoteKrbRelay Kerberos Relay Tool Execution
Flags and image indicators for RemoteKrbRelay execution on Windows, including relaying-related command-line actions.
sigmaWindowshigh2024-06-27Windows File Drop Indicators for RemoteKrbRelay SMB Relay Secret Dump Module
Alerts on creation of RemoteKrbRelay-specific temp files used to stage secrets dump outputs on Windows.
sigmaWindowshigh2024-06-27Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
sigmaWindowshigh2024-06-26SharpDPAPI Tool Execution via Command-Line and PE Metadata on Windows
Flags SharpDPAPI executions on Windows by combining SharpDPAPI PE metadata with distinctive DPAPI-related CommandLine arguments.
sigmaWindowshigh2024-06-26