Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
38 rules
Windows AppX Deployment: Uncommon Appx Path Added to Deployment Pipeline
Alerts when an AppX package is queued for processing from uncommon paths or URLs in Windows AppX deployment server events.
sigmaWindowsmedium2023-01-11Windows AppX Deployment Blocked by Local Policy
Detects blocked AppX package deployments on Windows via AppXDeployment-Server policy-denial Event IDs.
sigmaWindowsmedium2023-01-11Windows AppX Package Deployment: Suspicious AppX Installation Attempts by PackageFullName
Alerts on Windows AppX deployment events tied to a known-malicious AppX package identifier.
sigmaWindowsmedium2023-01-11Windows AppX Deployment: Staged Directory Package Added to Pipeline
Alerts when AppX deployment processing references a package located in typical staging directories such as Temp or Downloads.
sigmaWindowshigh2023-01-11Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
sigmaWindowshigh2023-01-11Windows AppX deployment blocked by AppLocker (AppXDeployment-Server EventID 412)
Flags AppX package deployment attempts that AppLocker blocked, based on AppXDeployment-Server EventID 412.
sigmaWindowsmedium2023-01-11Linux Package Installation via apt/yum/rpm/dpkg with Networking Tools Keywords
Alerts when apt/yum/rpm/dpkg install commands include reconnaissance or proxy tool keywords.
sigmaLinuxmedium2023-01-03Windows Registry: Appx DebugPath Key for Potential Persistence
Detects registry set activity involving AppX DebugPath entries that may indicate persistence via packaged app debug configuration.
sigmaWindowsmedium2022-07-27Windows File Creation of .diagcab Packages
Alerts on newly created Windows .diagcab files that may indicate malicious packaging or exploitation.
sigmaWindowsmedium2022-06-08Linux chmod Process Commandlines Targeting Sensitive Directory Paths
Flags Linux chmod commands that modify permissions for paths under /tmp/, /.Library/, /etc/, or /opt/, excluding several known benign package-maintenance patterns.
sigmaLinuxmedium2022-06-03Windows msiexec.exe Initiates Outbound HTTP(S) Connection on Port 80/443
Alerts when msiexec.exe starts outbound connections to ports 80 or 443, indicating potential remote package retrieval.
sigmalow2022-01-16Windows DNS Queries Triggered by DesktopAppInstaller AppInstaller.EXE
Identifies DNS lookups performed by Windows AppInstaller.EXE when initiating ms-appinstaller package installation from a URL.
sigmaWindowsmedium2021-11-24Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
sigmaWindowshigh2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
sigmaWindowshigh2020-10-29Windows AppLocker Blocked Application, Script, MSI, or Packaged-App Execution
Alerts on AppLocker event IDs showing blocked execution of apps, scripts, DLLs, MSI, or packaged apps.
sigmaWindowsmedium2020-06-28Windows processes accessing microphone and webcam via CapabilityAccessManager ConsentStore
Identifies Windows processes interacting with non-packaged app consent entries for microphone and webcam access.
sigmaWindowsmedium2020-06-07Windows: DXCap.exe Used with -c to Launch Arbitrary Binaries
Flags Windows executions of DXCap.EXE using -c, a pattern that can launch arbitrary binaries or packages.
sigmaWindowsmedium2019-10-26Windows Registry: New Security Support Provider (SSP) added to LSA configuration
Alerts when a new SSP is added to LSA Security Packages in the Windows registry, excluding msiexec-driven changes.
sigmaWindowshigh2019-01-18