Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Linux Service Reload/Start via systemctl or service Command Execution
Identifies Linux process executions invoking service control commands with start or reload keywords.
sigmaLinuxlow2019-09-23Linux auditd: chmod/chown process execution indicating file or folder permission changes
Flags Linux EXECVE events running chmod or chown, which commonly correspond to file/folder permission changes.
sigmaLinuxlow2019-09-23Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents
Alerts on non-interactive PowerShell spawned by atypical parent processes, excluding known update, VS Code, terminal, and defender-related parents.
sigmaWindowslow2019-09-12Cisco AAA keyword hits for data staging and file transfer commands (TFTP/RCP/PUT/COPY/ARCHIVE)
Flags Cisco AAA activity containing TFTP/RCP and copy/archive commands commonly used to stage data on devices.
sigmaNetworklow2019-08-12Cisco AAA discovery via show/dir commands
Alerts on Cisco AAA log entries with discovery-oriented 'dir' and 'show' command keywords.
sigmaNetworklow2019-08-12Cisco AAA Command Output Collection: show running/startup-config and archive config
Detects Cisco command strings attempting to collect device configuration via show running/startup/archived config.
sigmaNetworklow2019-08-11Windows Remote PowerShell via PS Classic (wsmprovhost.exe, HostName=ServerRemoteHost)
Flags Windows telemetry indicating a remote PowerShell session startup using wsmprovhost.exe with a specified host parameter.
sigmaWindowslow2019-08-10Windows Image Load: WMI DLLs Loaded by Uncommon Process
Alert on loading of common WMI DLLs by processes outside typical system/.NET paths.
sigmalow2019-08-10Windows Local User Creation (Security Event 4720)
Flags Windows Security Event ID 4720 indicating a local user account was created.
sigmaWindowslow2019-04-18Firewall Rule Accepting Cleartext Protocol Ports
Alerts on firewall-allowed traffic to common service ports that may carry credentials over unencrypted channels.
sigmaNetworklow2019-03-26Cleartext Authentication via Netflow to Common Service Ports
Alerts on Netflow flows to specific service ports that may indicate cleartext protocol use and potential credential exposure.
sigmalow2019-03-26Qualys: Alert When Firewall Product Is Not Detected on a Host
Alerts when Qualys reports a host missing a detectable firewall product during vulnerability management scanning.
sigmalow2019-03-19Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
sigmaWindowslow2019-02-23Windows Security Event 4616 for System Time Changes by Non-Service Accounts
Flags Windows Event 4616 system time changes when made by processes outside svchost.exe and common virtualization agents.
sigmaWindowslow2019-02-05Windows schtasks.exe Scheduled Task Creation by Non-Microsoft Office Integration
Alerts on schtasks.exe /create executions indicating scheduled task creation, with exclusions for Office integrator-related cases.
sigmaWindowslow2019-01-16Windows Process Creation: Execution of Net.exe or Net1.exe
Alerts on execution of net.exe/net1.exe with common net subcommands via Windows process creation and command-line telemetry.
sigmalow2019-01-16Windows NTLM authentication events (Event ID 8002)
Alerts on Windows NTLM authentication occurrences based on Event ID 8002 from Microsoft-Windows-NTLM/Operational.
sigmaWindowslow2018-06-08Windows Process Creation with taskmgr.exe as Parent Process
Flags process creation where taskmgr.exe is the parent, excluding a few known benign child process images.
sigmaWindowslow2018-03-13Windows Security Event 4719 Audit Policy Changes indicate Windows auditing disabled
Flags Windows Event Auditing disabled indicators from Security Event ID 4719 with removed success/failure audit policy.
sigmaWindowslow2017-11-19Windows Driver Frameworks: USB Device Plug/Unplug Events (Event IDs 2003, 2100, 2102)
Flags USB device plug/unplug related Driver Frameworks User-Mode events using Windows event IDs 2003, 2100, and 2102.
sigmaWindowslow2017-11-09