Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows .cpl Image Loads from Uncommon Paths Indicating Control Panel Abuse
Alerts on Windows loading of .cpl control panel items from uncommon paths instead of standard system directories.
sigmaWindowshigh2024-01-09Windows WFP 5157: Connection Blocked for EDR Agent Binaries
Flags WFP blocked connections (EventID 5157) when an EDR/security agent binary is the blocked application.
sigmaWindowshigh2024-01-08Windows forfiles.exe Spawned cmd.exe from Non-System Location
Alerts on forfiles.exe running outside system paths and spawning cmd.exe with a forfiles-encoded command pattern.
sigmaWindowshigh2024-01-05Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
Alerts on Windows Filtering Platform policy change events containing "RonPolicy" consistent with NoFilter abuse.
sigmaWindowshigh2024-01-05Windows Process Creation: EDRSilencer Executed
Flags execution of EDRSilencer.exe on Windows based on process image and identifying metadata.
sigmaWindowshigh2024-01-02Windows Process Execution of Renamed cloudflared.exe with Tunnel/Run Command Arguments
Alerts on Windows process executions of renamed cloudflared with tunnel run/cleanup command-line arguments or matching SHA-256 hashes.
sigmaWindowshigh2023-12-20macOS Bash Pipelines Extract Image Bytes and Base64-Decode Output to a File
Alerts on bash on macOS that tails image bytes, base64-decodes them, and writes decoded output to a new file.
sigmamacOShigh2023-12-20Windows Task Scheduler: SVR Scheduled Task Names (GraphicalProton) Matching
Flags Windows scheduled task creation, update, or deletion when task names match known SVR GraphicalProton backdoor strings.
sigmahigh2023-12-18Windows Scheduled Task Creation Using SVR-Specific Task Names
Alerts on Windows scheduled task events with SVR-associated task names indicative of persistence.
sigmahigh2023-12-18Windows Registry: Set LSA NoLMHash to 0 to Enable LM Hash Storage
Flags changes to NoLMHash (DWORD 0) enabling Windows to store LM password hashes.
sigmaWindowshigh2023-12-15Windows Process Creation: Enable LM Hash Storage via Lsa\NoLMHash=0 in Command Line
Flags process command lines that set Lsa\NoLMHash to 0 to enable LM hash storage.
sigmaWindowshigh2023-12-15Windows Registry: HVCI disallowed image list modified (HVCIDisallowedImages)
Alerts when Windows HVCI disallowed images registry value is modified, indicating potential driver load policy tampering.
sigmaWindowshigh2023-12-05Windows process command line matches WinPwn tool execution keywords
Alerts on Windows process executions with command-line keywords associated with WinPwn (WinPwn.exe/ps1/offline mode).
sigmaWindowshigh2023-12-04Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.
sigmaWindowshigh2023-12-04Windows: Netsh helper DLL registration via suspicious registry paths
Flags Netsh helper DLL registration when the DLL path is found in suspicious user/temp-like registry details on Windows.
sigmaWindowshigh2023-11-28Windows Image Load of RstrtMgr.dll by Suspicious Path or User Content
Alerts on RstrtMgr.dll loading from suspicious path contexts using Windows image load telemetry.
sigmaWindowshigh2023-11-28Detect CVE-2023-4966 Citrix ADC Sensitive Info Disclosure Attempts in Webserver Logs via Long Host Header
Alerts on GET requests to the OpenID configuration endpoint with an unusually long Host header, indicative of CVE-2023-4966 probing.
sigmahigh2023-11-28Citrix ADC CVE-2023-4966 Proxy Exploitation Attempt via Oversized Host Header (GET /oauth idp well-known)
Flags proxy GETs to the OpenID configuration endpoint with an excessively long Host header consistent with CVE-2023-4966 probing.
sigmahigh2023-11-28Python-Based Tool LSASS Process Access for Credential Dumping (Windows)
Alerts on process-access attempts to lsass.exe with a Python-related call trace and high granted access.
sigmaWindowshigh2023-11-27Windows HackTool Process Access: Detect Access by Common Tool Image Names
Alerts on Windows process access events initiated by processes whose image names match common credential/dumping hack tools.
sigmaWindowshigh2023-11-27