Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Linux process activity: chown root and setuid/setgid chmod flags
Alerts on Linux command lines that set root ownership and enable setuid/setgid via chmod u+s or g+s.
sigmaLinuxlow2020-06-16Zeek: Detect WebDAV User-Agent with HTTP PUT to local or RFC1918 addresses
Flags Zeek HTTP PUT requests with a WebDAV User-Agent that target non-excluded network addresses.
sigmaNetworklow2020-05-02Windows Image Load of System.Drawing.ni.dll
Alerts when a Windows process loads System.Drawing.ni.dll, which may indicate visual data collection activity.
sigmalow2020-05-02Windows PFX File Creation From File Events
Flags Windows file events where a .pfx (certificate + private key) is created, excluding a few common benign locations.
sigmalow2020-05-02AWS CloudTrail EC2 CreateInstanceExportTask Failure
Flags failed EC2 VM export task creation events in AWS CloudTrail to surface potential instance data extraction attempts.
sigmaCloudlow2020-04-16Successful Windows Account Logon via WMI (4624 with WmiPrvSE.exe)
Flags successful 4624 logons tied to WmiPrvSE.exe, indicating WMI-driven authentication on Windows.
sigmaWindowslow2019-12-04Windows Security Event 6416 for USB Mass Storage Device Plug-In or DiskDrive Recognition
Flags Windows Event ID 6416 entries where a DiskDrive/USB Mass Storage Device is detected as connected.
sigmaWindowslow2019-11-20Windows System Time Discovery via net.exe or w32tm.exe
Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.
sigmaWindowslow2019-10-24Windows hh.exe Execution Triggered by .chm Command Line
Flags hh.exe being executed with a command line referencing a .chm file on Windows.
sigmaWindowslow2019-10-24Windows Security 4697: TAP Driver Service Installation (tap0901)
Alerts on Windows Security EID 4697 service installation events for TAP driver files containing "tap0901."
sigmaWindowslow2019-10-24Linux auditd: dd overwrites a file using /dev/null or /dev/zero
Flags dd command lines that overwrite files by sourcing data from /dev/null or /dev/zero.
sigmaLinuxlow2019-10-23Windows Raw Disk Access by Uncommon Process Paths
Alerts on Windows raw disk access by processes from uncommon or suspicious locations.
sigmaWindowslow2019-10-22Windows Local Account Discovery via System Utilities Process Execution
Flags Windows processes that match utilities used to enumerate local user and account information.
sigmaWindowslow2019-10-21Windows Rar.exe Files Added to Archive Activity
Alerts when Windows rar.exe is used to add files to an archive using the " a " command-line pattern.
sigmaWindowslow2019-10-21Windows: net.exe used to start a service with the start flag
Identifies Windows processes using net.exe/net1.exe with ' start ' to start services.
sigmaWindowslow2019-10-21Windows Process: File Association Changes via assoc Command
Alerts on cmd.exe launches running the assoc command to modify Windows default file associations.
sigmaWindowslow2019-10-21Linux System Owner or User Discovery via Common Utility Execution
Flags execution of Linux user/system identification utilities such as whoami and id.
sigmaLinuxlow2019-10-21Linux: Detect execution of tcpdump or tshark with interface (-i) capture option
Alerts on tcpdump or tshark executions on Linux where an interface flag is present, consistent with network sniffing.
sigmaLinuxlow2019-10-21Linux Auditd: Command Execution of zip, gzip -k, or tar -c for Data Compression
Alerts on Linux execve events launching zip, gzip (-k), or tar create commands often used to compress data.
sigmaLinuxlow2019-10-21PowerShell Compress-Archive Cmdlet Execution for Data Compression
Flags PowerShell scripts using the Compress-Archive cmdlet, consistent with local data packaging before collection or exfiltration.
sigmalow2019-10-21