Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Splunk Enterprise RCE Exploitation Attempt via XML Upload and Search Job Requests
Flags Splunk web exploitation patterns for CVE-2023-46214 using shell.xsl uploads followed by search-result URIs.
sigmahigh2023-11-27wusa.exe Execution with Parent in Suspicious Windows Paths
Alerts when wusa.exe is spawned by a parent running from common suspicious Windows directories, excluding .msu-related noise.
sigmaWindowshigh2023-11-26Windows Registry IME File Value Used from Suspicious Paths
Alerts on Windows keyboard layout "Ime File" registry entries pointing to suspicious writable directory paths.
sigmaWindowshigh2023-11-21Windows Registry: Uncommon IME File Value in Keyboard Layouts Path
Alerts on Control\Keyboard Layouts\ registry values named "Ime File" that reference non-.ime extensions.
sigmaWindowshigh2023-11-21CVE-2023-22518 Confluence Exploitation Attempt via Suspicious Bash/Curl/Wget Child Processes on Linux
Alerts when Confluence Java spawns shell/download tools on Linux consistent with CVE-2023-22518 exploitation behavior.
sigmahigh2023-11-14Windows Process Creation: Excel DCOM Child Processes Linked to ActivateMicrosoftApp
Alerts when excel.exe spawns foxprow.exe, schdplus.exe, or winproj.exe, consistent with suspicious Excel DCOM automation activity.
sigmaWindowshigh2023-11-13Windows msxsl.exe Execution with HTTP Keyword in Command Line
Flags execution of msxsl.exe when the command line includes an HTTP URL indicator.
sigmaWindowshigh2023-11-09Windows Process Creation: Detect IMEWDBLD.EXE Downloading Files via HTTP/HTTPS
Alerts when IMEWDBLD.exe runs with an HTTP/HTTPS URL, indicating arbitrary file downloads.
sigmaWindowshigh2023-11-09Windows: Detect SysAid user.exe Loader Execution by Filename and SHA256 Hash
Flags execution of a specific SysAid-hosted Windows binary when the process image path and SHA256 match.
sigmahigh2023-11-09Windows Process Execution for PowerShell Cobalt Strike Download via Hidden IEX
Flags PowerShell command lines that use IEX and hidden downloadstring to fetch a Cobalt Strike payload.
sigmahigh2023-11-09Windows PowerShell script launcher matching SysAidServer Tomcat paths
Flags PowerShell script block text tied to SysAid Tomcat webapp paths and user.exe staging/launch actions.
sigmahigh2023-11-09PowerShell Script Evidence Eraser Searching for cleanLL and usersfiles.war
Identifies PowerShell script blocks containing evidence-cleanup indicators and a repeating while(1) loop.
sigmahigh2023-11-09Windows PowerShell Script File Creation: SysAidServer Webapp User/User.exe Indicators
Detects creation of specific SysAidServer Tomcat webapp files indicative of PowerShell script staging on Windows.
sigmahigh2023-11-09F5 BIG-IP Webserver RCE exploitation attempts via POST to /mgmt/tm/util/bash
Alerts on POST requests to /mgmt/tm/util/bash containing tmui Control/form parameters consistent with CVE-2023-46747 exploitation attempts.
sigmahigh2023-11-08F5 BIG-IP Proxy: Detect POST requests exploiting CVE-2023-46747 via /mgmt/tm/util/bash
Alerts on POST requests containing /mgmt/tm/util/bash plus TMUI control/user-create form parameters indicative of CVE-2023-46747 exploitation.
sigmahigh2023-11-08Windows Registry: Disabling Antivirus Filter Driver on Dev Drive via FltmgrDevDriveAllowAntivirusFilter
Detects registry changes disabling antivirus minifilter inspection on a Dev Drive by setting the allow setting to 0x0.
sigmaWindowshigh2023-11-05Windows image load and execution of unsigned Thor scanner (thor.exe/thor64.exe)
Alerts on thor.exe/thor64.exe image loads on Windows where the Authenticode signature is missing or not from Nextron Systems.
sigmaWindowshigh2023-10-29Windows Process Creation: rundll32 Spawns Pikabot-Like Hollowing Binaries
Alerts when rundll32.exe spawns specific Windows binaries in patterns consistent with potential process hollowing.
sigmahigh2023-10-27Windows Process Creation Signals for Pikabot System Discovery
Flags process-launch discovery commands (ipconfig/netstat/whoami) under rundll32 and Search host parent processes on Windows.
sigmahigh2023-10-27Windows file creation of code_tunnel.json outside Code/VsCode executables
Alerts on creation of code_tunnel.json on Windows when it isn’t created by typical VS Code binaries.
sigmaWindowshigh2023-10-25