Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows File Creation: inetmgr.exe in \Windows\ADFS\bg\ Path
Alerts on creation of \Windows\ADFS\bg\inetmgr.exe in Windows file events.
sigmahigh2023-10-24Windows Registry Events: Scheduled Task Creation via TaskCache Tree Key
Flags registry activity creating TaskCache Tree entries tied to TeamCity settings UI during exploitation.
sigmahigh2023-10-24Windows Process Creation Command-Line Indicator Matching 'uTYNkfKxHiZrx3KJ'
Triggers on Windows process creation events with command line containing 'uTYNkfKxHiZrx3KJ'.
sigmahigh2023-10-24Windows DLL Side-Loading via ProgramData Image Load Indicators (clip.exe and wsmprovhost.exe)
Flags ProgramData clip.exe or wsmprovhost.exe launching with suspicious DLL loads from ProgramData.
sigmahigh2023-10-24Windows File Creation Indicators Linked to Diamond Sleet Artifacts
Flags Windows file creations under \ProgramData matching specific payload component filename indicators.
sigmahigh2023-10-24Windows DNS queries containing Diamond Sleet–related domains
Alerts on Windows DNS queries for QueryName values containing specific Diamond Sleet–related domains.
sigmahigh2023-10-24Web exploitation attempts for CVE-2023-43261 causing info disclosure in Milesight routers
Alerts on successful GET requests for /lang/log/httpd.log in Milesight router web access logs, consistent with CVE-2023-43261 disclosure attempts.
sigmahigh2023-10-20Potential Information Disclosure via CVE-2023-43261 in Milesight Router Proxy Logs
Alerts on HTTP GET 200 responses for UR router log paths in proxy requests associated with CVE-2023-43261.
sigmahigh2023-10-20Cisco IOS XE Web UI Exploitation Indicators for CVE-2023-20198 via Syslog Login and Config Events
Matches Cisco IOS XE Web UI and web login success logs consistent with CVE-2023-20198 exploitation using specified admin/TAC usernames.
sigmahigh2023-10-20Windows Task Manager Creating lsass.dmp in Temp
Alerts when Task Manager creates a Temp lsass .DMP file consistent with LSASS memory dumping.
sigmaWindowshigh2023-10-19Windows CertOC.exe Downloads File From IP-Based URL Using -GetCACAPS
Flags CertOC.exe executions using an IP-based URL in the command line with -GetCACAPS.
sigmaWindowshigh2023-10-18Windows DLL Sideloading via ImageLoad of mscoRee/colorui/mapistub/HID payload DLLs
Alerts on Windows processes loading DLLs from targeted ProgramShared/ProgramData paths consistent with DLL sideloading.
sigmahigh2023-10-18DarkGate-related Autoit3.exe execution with suspicious parent process (Windows)
Alerts on AutoIt3.exe execution when spawned from cmd.exe, KeyScramblerLogon.exe, or msiexec.exe, excluding common legitimate install paths.
sigmahigh2023-10-15Windows Process Creation: CoercedPotato.exe Execution via ExploitId Parameters
Flags Windows process creation for CoercedPotato.exe with --exploitId and known IMPHASH values.
sigmaWindowshigh2023-10-11Windows Named Pipe Creation with "\coerced\" PipeName Segment
Detects Windows named pipe creations where the pipe name contains the '\coerced\' pattern.
sigmaWindowshigh2023-10-11Windows: Suspicious HTA Startup Folder Creation by FoxitPDFReader.exe
Alerts on FoxitPDFReader.exe creating .hta files in the Startup Programs folder, which can indicate persistence.
sigmahigh2023-10-11Windows Process Creation: Visual Studio Code Tunnel Execution with Renamed Binary
Flags Windows process executions that match renamed VS Code tunnel invocation patterns and related internal service startup.
sigmaWindowshigh2023-09-28AWS CloudTrail: AWS Identity Center Identity Provider Configuration Changes
Detects CloudTrail identity center events that associate or change the external identity provider configuration.
sigmaCloudhigh2023-09-27Windows AddInUtil.exe Executed with Suspicious AddInRoot or PipelineRoot Parameters
Alerts on AddInUtil.exe runs using uncommon AddInRoot/PipelineRoot values targeting Temp, Desktop, Downloads, or public user paths.
sigmaWindowshigh2023-09-18Windows network connections initiated by AddinUtil.exe
Alerts on network connections initiated by Addinutil.exe, which is uncommon for this utility on Windows.
sigmaWindowshigh2023-09-18