Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
528 rules
Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
sigmaWindowshigh2021-06-03Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Alerts on Windows 7045 service installs with ImagePath patterns consistent with Cobalt Strike-style PowerShell and execution.
sigmaWindowscritical2021-05-26Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
sigmaWindowshigh2021-05-26Windows Process Creation: PsExec/PAExec Flags Indicating SYSTEM Execution
Flags indicating PsExec/PAExec-style execution as LOCAL SYSTEM using cmd/powershell/pwsh in process command lines.
sigmaWindowshigh2021-05-22PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
sigmaWindowshigh2021-05-18PowerShell Defender Exclusion via Set/Add-MpPreference Command-Line Flags (Windows)
Detects PowerShell commands that add or set Microsoft Defender exclusions using Add/Set-MpPreference parameters.
sigmaWindowsmedium2021-04-29Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
sigmaWindowshigh2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
sigmaWindowshigh2021-04-23PowerShell ScriptBlock Certificate Export via Export-PfxCertificate or Export-Certificate
Detects PowerShell script blocks invoking certificate export cmdlets, which may be abused to steal sensitive certificate material.
sigmaWindowsmedium2021-04-23Windows Process Creation: Exchange PowerShell Snap-in Loading via Add-PSSnapin
Flags PowerShell executions that Add-PSSnapin Exchange snap-ins, consistent with Exchange mailbox/config data collection.
sigmaWindowshigh2021-03-03Windows PowerShell TcpClient reverse-shell connection attempt via Net.Sockets
Alerts on PowerShell processes launching with .NET TcpClient stream/write patterns consistent with reverse TCP connectivity.
sigmaWindowshigh2021-03-03Windows PowerShell Command Lines with WMI Process Creation and rundll32 Invocation
Flags Windows command lines where PowerShell/WMI is used to spawn rundll32 from c:\windows.
sigmacritical2021-01-20Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
sigmaWindowshigh2020-10-28Windows PowerShell Process Creation: COMPRESS OBFUSCATION with ASCII Encoding and DeflateStream
Flags PowerShell process creation command lines that use ASCII encoding plus compression/stream-reading patterns associated with obfuscation.
sigmaWindowsmedium2020-10-18PowerShell ScriptBlock Logging: Obfuscated RUNDLL Launcher using rundll32.exe and shell32.dll
Identifies PowerShell script content invoking rundll32.exe/shell32.dll via shellexec_rundll and referencing PowerShell.
sigmaWindowsmedium2020-10-18Detect PowerShell COMPRESS OBFUSCATION using ASCII text encoding and stream/compression APIs
Flags PowerShell script blocks that combine ASCII encoding with Deflate/stream handling indicative of obfuscated payload compression.
sigmaWindowsmedium2020-10-18PowerShell module activity launching rundll32 via shell32.dll obfuscation content
Alerts when PowerShell module payloads reference a shell32/rundll32 launcher pattern that includes PowerShell.
sigmaWindowsmedium2020-10-18PowerShell Module Payload Obfuscation Using COMPRESS OBFUSCATION
Identifies PowerShell module payloads containing ASCII encoding and compression/stream obfuscation strings.
sigmaWindowsmedium2020-10-18Windows System: Detect rundll32 Service Control Manager launches PowerShell via obfuscated parameters
Flags service creation where ImagePath uses rundll32/shell32 (shellexec_rundll) to invoke PowerShell.
sigmaWindowsmedium2020-10-18Windows System: Service Control Manager PowerShell Obfuscation Using COMPRESS OBFUSCATION
Flags new Windows services whose ImagePath includes obfuscated PowerShell markers using COMPRESS/stream decompression.
sigmaWindowsmedium2020-10-18