Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
GitHub Audit: Secret Scanning Push Protection Disabled
Alerts on GitHub audit log events where secret scanning push protection is disabled for org, repo, or custom patterns.
sigmahigh2024-03-07Windows Process Creation: rundll32 Shell32 Control_RunDLL Executes .CPL from User Temp
Detects rundll32 Shell32 Control_RunDLL launching a .CPL from user Temp, a stealthy execution path.
sigmahigh2024-03-07Windows ScreenConnect Service Web Shell Execution via cmd.exe or csc.exe
Alert on ScreenConnect.Service.exe spawning cmd.exe or csc.exe, consistent with potential web shell execution on Windows.
sigmaWindowshigh2024-02-26Bitbucket Audit: Secret Scanning Exempt Repository Added
Flags Bitbucket audit events where a repository is added as exempt from secret scanning.
sigmahigh2024-02-25Bitbucket Audit: Full Data Export Triggered
Alerts when Bitbucket audit logging records a full data export being triggered.
sigmahigh2024-02-25Windows Suspicious Wget.exe Downloads From IP to Common Staging Paths
Flags wget.exe on Windows downloading from an IP over HTTP and saving to common staging/user directories.
sigmaWindowshigh2024-02-23Windows: User Added to Highly Privileged Local/Directory Groups via net.exe or Add-LocalGroupMember
Flags net.exe or PowerShell commands adding users to privileged groups like Group Policy Creator Owners or Schema Admins.
sigmaWindowshigh2024-02-23Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
sigmaWindowshigh2024-02-23Windows File Events Indicative of SlashAndGrab ScreenConnect Post-Exploitation
Alerts on Windows file activity writing known SlashAndGrab-related ScreenConnect artifact paths and executables.
sigmahigh2024-02-23Windows DNS Queries to Known DPRK C2 Domains
Flags Windows DNS queries for specific DPRK-attributed C2 domain names.
sigmahigh2024-02-20Proxy Detection: Cobalt Strike Malleable C2 Profile HTTP URI/User-Agent/Method Patterns
Flags proxy HTTP requests whose URI, method, User-Agent, host, and cookie fragments match known Cobalt Strike malleable profile patterns.
sigmaWebhigh2024-02-15FortiOS sslvpnd CVE-2022-42475 Exploitation Indicator Keyword Matching
Flags FortiOS sslvpnd activity containing known CVE-2022-42475 artifact paths from file-related events.
sigmahigh2024-02-08Windows iexpress.exe Creates Self-Extracting Binaries Using SED Files From Suspicious Paths
Flags suspicious use of Windows iexpress.exe to create self-extracting packages via SED directives from uncommon/temp paths.
sigmaWindowshigh2024-02-05Windows SharpMove (.NET) Execution via SharpMove.exe and Action Command-Line Flags
Alerts on SharpMove.exe process execution with command-line actions for DCOM, WMI VBS, and task scheduler.
sigmaWindowshigh2024-01-29Windows EDRSilencer Execution via Filtering Platform FilterName Change
Detects Filtering Platform custom outbound filter additions associated with potential EDRSilencer execution on Windows.
sigmaWindowshigh2024-01-29Windows Process Creation: SOAPHound Execution via AD Data Collection Command-Line Arguments
Flags SOAPHound execution on Windows by detecting command-line arguments used for Active Directory data collection.
sigmaWindowshigh2024-01-26Windows: Suspicious rundll32 Execution of Non-DLL Extension via Living-off-the-Land Parent Processes
Flags rundll32.exe executions from common script parents where the command line references known drop locations but lacks standard extensions.
sigmahigh2024-01-26Windows process creation matching specific Peach Sandstorm command-line indicator
Alerts on Windows process creations whose command line contains a specific suspicious substring.
sigmahigh2024-01-15Windows: Detect renamed PingCastle binary execution via PE metadata and scanner command-line
Flags Windows processes that look like renamed PingCastle executables using PE original file names and PingCastle scanner/healthcheck arguments.
sigmaWindowshigh2024-01-11Windows PingCastle Execution From Suspicious Parent Processes
Alerts on PingCastle (PingCastle.exe) being run with full scan/healthcheck arguments from potentially suspicious parent process locations.
sigmaWindowshigh2024-01-11