Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
sigmaWindowshigh2024-06-26Windows File Writes Matching DPAPI Backup Key and Certificate Export Filenames
Alerts on Windows file events for DPAPI backup key/certificate filenames ending in .cer/.key/.pfx/.pvk.
sigmaWindowshigh2024-06-26Windows CSharp Streamer RAT Potentially Loaded .NET Executable from Temp dat####.tmp
Identifies .NET executable image loads from a CSharp Streamer RAT-like Temp .tmp path pattern on Windows.
sigmahigh2024-06-22Windows Network Connections to LocaltoNet/Localtonet Tunneling Subdomains
Alerts on initiated outbound connections from Windows hosts to LocaltoNet/.localtonet.com tunneling domains.
sigmaWindowshigh2024-06-17Linux: Network connections initiated to LocaltoNet tunneling subdomains
Alerts when a Linux host initiates outbound connections to LocaltoNet (.localto.net/.localtonet.com) tunneling subdomains.
sigmaLinuxhigh2024-06-17Windows: File Creation by mysqld.exe With Script/Executable Extensions
Alerts on file creation by mysqld.exe producing .bat/.exe/.ps1/.vbs and other executable or script file types on Windows.
sigmaWindowshigh2024-05-27Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
sigmaWindowshigh2024-05-10Windows Process Creation: wbadmin.exe Triggered for Backup of Sensitive Registry and NTDS Files
Alerts on wbadmin.exe backup commands that reference SAM/SECURITY/SYSTEM hives or NTDS.DIT.
sigmaWindowshigh2024-05-10Proxy WebDAV MiniRedir Drives Execution from External Shares
Alert on external WebDAV MiniRedir GET requests for executable-like file extensions that may lead to execution.
sigmaWebhigh2024-05-10Linux network connections to known malware callback ports
Alerts on initiated Linux outbound connections to specific known suspicious destination ports, excluding local/private IP ranges.
sigmaLinuxhigh2024-05-10Windows: Alert on Outbound Connections Initiated by dialer.exe (Microsoft Phone Dialer)
Alerts on outbound connections started by Windows dialer.exe, excluding common local and reserved IP ranges.
sigmaWindowshigh2024-04-26Windows Registry Set: Custom Protocol Handler DLL for CLSID {026CC6D7-34B2-33D5-B551-CA31EB6CE345}
Alerts when a Windows registry entry for a specific custom protocol handler CLSID is set to a DLL.
sigmahigh2024-04-23Windows Process Creation: Forest Blizzard-related hashes and scheduled task activity
Detects suspicious Windows process execution tied to known hashes or schtasks/PowerShell command-line patterns used for staging and compression.
sigmahigh2024-04-23Windows File Creation: ProgramData Persistence Artifacts Matching
Alerts on Windows file creations in C:\ProgramData matching specific driver inf, .dll, and batch/script filename patterns.
sigmahigh2024-04-23Suspicious Palo Alto GlobalProtect Session Unmarshal Path Traversal and Command Injection Attempts
Detects GlobalProtect logs with directory traversal/command injection-style indicators tied to CVE-2024-3400 behavior.
sigmahigh2024-04-18Windows DLL side-loading: KeyScramblerIE.DLL loaded by KeyScrambler.exe
Alerts on KeyScrambler.exe loading KeyScramblerIE.dll, a common DLL side-loading pattern that may indicate malicious library execution.
sigmaWindowshigh2024-04-15Linux sshd Spawns Root Shell Script Commands Suggesting CVE-2024-3094 Exploitation
Alerts on sshd spawning bash/sh one-liners as root, a potential indicator of CVE-2024-3094 style exploitation.
sigmahigh2024-04-01Winlogon Shell Registry Persistence Attempt (KamiKakaBot Indicators) on Windows
Flags registry changes to Winlogon Shell that include PowerShell-style startup and explorer.exe indicators.
sigmahigh2024-03-22Progress Kemp LoadMaster Unauthenticated Command Injection via /access/set GET Parameters
Alerts on suspicious LoadMaster /access/set GET requests with enableapi/value=1 and anomalous Basic Authorization header content.
sigmahigh2024-03-20Windows Execution of Renamed NirCmd.exe (nircmd.exe/nircmdc.exe) via PE OriginalFileName
Alerts when a process uses NirCmd.exe PE metadata while the executable name is renamed to nircmd.exe or nircmdc.exe.
sigmaWindowshigh2024-03-11