Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Watch: PythonFunctionWarnings Disabled via Excel Security Registry Setting
Flags Excel-related process command lines that disable Python function execution warnings via PythonFunctionWarnings=0.
sigmaWindowshigh2023-08-22Azure Entra ID Riskdetection: Anonymous IP Address sign-in risk events
Detects Azure sign-in risk events labeled as anonymized/anonymous IP addresses.
sigmaCloudhigh2023-08-22Suspicious Child Process Creation from BgInfo.EXE on Windows
Alerts when BgInfo.exe spawns suspicious calc/cmd/cscript/mshta/powershell/wscript or runs from common AppData/Temp paths.
sigmaWindowshigh2023-08-16Suspicious aspnet_compiler.exe Execution from User or Temp Paths on Windows
Alerts when aspnet_compiler.exe runs with command lines indicating user-writable or temp/task paths.
sigmaWindowshigh2023-08-14Suspicious Child Process of aspnet_compiler.exe on Windows
Alerts when aspnet_compiler.exe spawns calc/notepad or executes from public/temp/Task-related paths on Windows.
sigmaWindowshigh2023-08-14Windows DLL sideloading via unsigned mfdetours.dll loaded by image_load
Alerts on loading unsigned \mfdetours.dll, consistent with DLL sideloading abuse via mftrace.exe.
sigmaWindowshigh2023-08-11Windows Process Creation: Execution of Renamed gpg.exe or gpg2.exe
Alerts on Windows executions of renamed gpg.exe/gpg2.exe using process creation telemetry.
sigmaWindowshigh2023-08-09Windows Provisioning Registry Key Abuse Leading to Indirect Execution via Provlaunch.exe
Flags Windows command lines referencing the provisioning commands registry path commonly abused for Provlaunch.exe-based indirect execution.
sigmaWindowshigh2023-08-08Windows: Alert on Suspicious Child Processes Spawned by provlaunch.exe
Detects provlaunch.exe launching suspicious child executables and processes from common temp/task paths on Windows.
sigmaWindowshigh2023-08-08Azure risk detection: anomalousToken risk events
Flags Azure Entra ID risk events indicating anomalous token lifetime or use from unfamiliar locations.
sigmaCloudhigh2023-08-07Windows Browser-Injected rundll32 Execution Indicative of GuLoader Activity
Flags rundll32.exe being launched from a browser process, matching GuLoader-style injected browser execution behavior on Windows.
sigmahigh2023-08-07Windows ImageLoad DLL Sideloading: EACore.dll
Alerts on Windows loading of EACore.dll that may indicate DLL sideloading, excluding a specific EA Desktop legitimate case.
sigmaWindowshigh2023-08-03Windows Registry Key Abuse via Provisioning Commands for Proxy Binary Execution
Flags registry modifications to the Provisioning Commands key path that may enable indirect execution via Provlaunch.exe.
sigmaWindowshigh2023-08-02Windows AppCompatFlags InstalledSDB New Shim Database in Non-Default Path
Flags persistence attempts where a shim database is registered via InstalledSDB with a non-default DatabasePath on Windows.
sigmaWindowshigh2023-08-01Windows Registry: New AppCompatFlags custom shim databases targeting system processes
Alerts on Windows registry writes to AppCompatFlags Custom shim paths targeting common system processes.
sigmaWindowshigh2023-08-01Windows VMMap Loading Unsigned dbghelp.dll from C:\Debuggers\dbghelp.dll
Alerts when VMMap loads an unsigned dbghelp.dll from C:\Debuggers, suggesting DLL sideloading on Windows.
sigmaWindowshigh2023-07-28Windows CreateRemoteThread in mstsc.exe From Suspicious Source Paths
Alerts when mstsc.exe creates remote threads from processes running out of common suspicious directories.
sigmaWindowshigh2023-07-28Windows: Alert on wget.exe downloading files from an IP with output flags
Flags Windows wget.exe usage to download HTTP URLs from IPs and write outputs to script/binary extensions.
sigmaWindowshigh2023-07-27Suspicious curl.exe File Downloads From Direct IP Addresses on Windows
Alerts on Windows curl.exe commands downloading from an IP address with HTTP/S and suspect file extensions.
sigmaWindowshigh2023-07-27Sysmon FileBlockShredding Policy Violations (Event ID 28) on Windows
Alerts on Sysmon Event ID 28 when file shredding is blocked by the configured shredding policy on Windows.
sigmaWindowshigh2023-07-20