Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Proxy downloads of executable and document files from suspicious TLDs (blacklisted domains)
Alerts when proxy users download common malware and lure file types from hosts using suspicious TLDs.
sigmaWeblow2017-11-07Windows: Administrator Account Remote Logon via Negotiate (4624 LogonType 10)
Alerts on remote logons to admin-named accounts in Windows Security logs (4624, LogonType 10, Negotiate).
sigmaWindowslow2017-10-29Windows Registry Key Created: Sysinternals EULA Acceptance
Flags registry writes indicating Sysinternals EULA acceptance via a TargetObject ending with \EulaAccepted.
sigmaWindowslow2017-08-28Windows: Command-line execution using Sysinternals -accepteula flag
Alerts on Windows processes launched with the -accepteula flag, often associated with Sysinternals tool execution.
sigmaWindowslow2017-08-28Windows: PsExec Service File Creation via PSEXESVC.exe Written to Disk
Flags Windows file creation of \PSEXESVC.exe, indicating potential PsExec service deployment for remote execution.
sigmaWindowslow2017-06-12Windows Named Pipe Creation for PsExec Default Pipe
Alerts on creation of the default PsExec named pipe (\\PSEXESVC) using Windows named pipe creation telemetry.
sigmalow2017-06-12Proxy: Block Suspicious Executable Downloads from Non-Trusted Top-Level Domains
Finds proxy traffic requesting executable or script/doc payloads from hosts with suspicious TLDs not in the whitelist.
sigmaWeblow2017-03-13Windows Network Connections Initiated by PowerShell (powershell.exe or pwsh.exe)
Flags outbound network connections initiated by PowerShell on Windows, excluding common local and private IP ranges.
sigmalow2017-03-13PowerShell Net.WebClient DownloadFile/DownloadString Usage (Classic)
Flags PowerShell Classic commands using Net.WebClient to download content via DownloadFile or DownloadString.
sigmaWindowslow2017-03-05Windows: Detects Access to ADMIN$ Network Share (Event 5140)
Alerts on Windows Security event 5140 entries where an access request targets the ADMIN$ share.
sigmaWindowslow2017-03-04