Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
38 rules
Windows Office Child Process with Directory Traversal Patterns
Alerts on Office parent processes launching child commands containing directory traversal patterns.
sigmahigh2022-06-02Windows msdt.exe Execution with Suspicious Parent Process
Alerts when msdt.exe runs under common command-and-script or utility parent processes on Windows.
sigmaWindowshigh2022-06-01Windows: rundll32.exe launched by explorer.exe parent process
Alerts when explorer.exe spawns rundll32.exe with specific command-line characteristics on Windows.
sigmaWindowsmedium2022-05-21Windows Suspicious Parent Processes: Unusual Child Creation by System Utilities
Alerts when predefined suspicious Windows parent executables spawn unusual or unrecognized child processes.
sigmaWindowshigh2022-03-21Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Flags web server processes spawning child commands consistent with credential dumping, exfiltration, and privilege changes.
sigmaWindowshigh2022-03-17Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Alerts on processes launched from \Users\Public that execute common scripting/shell binaries or command-line markers.
sigmaWindowshigh2022-02-25Windows Office Macro File Creation Triggered by Script/LOLBin Parent Process
Alerts when macro-enabled Office files are created by common Windows script execution processes.
sigmaWindowshigh2022-01-23Windows UAC Bypass via ComputerDefaults.exe with Elevated Integrity Parent Process
Flags ComputerDefaults.exe runs at high/system integrity when the parent isn’t from typical system or Program Files paths.
sigmaWindowshigh2021-08-31Windows whoami.exe Execution from Suspicious Parent Processes
Alerts on whoami.exe runs where the parent process is not a typical shell or monitoring agent.
sigmaWindowsmedium2021-08-12Windows: Time Travel Debugging Utility (tttracer.exe) Process Execution
Alerts when tttracer.exe is the parent process of a spawned process on Windows.
sigmaWindowshigh2020-10-06Windows PowerShell execution with uncommon/suspicious parent process
Alerts when PowerShell is started from certain unusual parent processes that commonly indicate abuse.
sigmaWindowshigh2020-03-20Windows remote PowerShell session activity via wsmprovhost.exe process relationships
Alerts when wsmprovhost.exe is seen as a process or parent process, indicating remote PowerShell via WinRM.
sigmaWindowsmedium2019-09-12Windows: Non-interactive PowerShell (powershell.exe/pwsh.exe) spawned from GUI or updater parents
Alerts on non-interactive PowerShell spawned by atypical parent processes, excluding known update, VS Code, terminal, and defender-related parents.
sigmaWindowslow2019-09-12Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Alerts when a new process is spawned under a Terminal Services (termsvcs) host context in Windows.
sigmaWindowshigh2019-05-22Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
sigmaWindowslow2019-02-23Windows: Alert on suspicious parent process spawning csc.exe
Flags csc.exe execution when spawned by script/document hosts or PowerShell using encoded content, excluding common benign parent contexts.
sigmaWindowshigh2019-02-11Windows Process Creation with taskmgr.exe as Parent Process
Flags process creation where taskmgr.exe is the parent, excluding a few known benign child process images.
sigmaWindowslow2018-03-13Windows svchost.exe Spawned by Uncommon Parent Process
Alerts when svchost.exe starts with an unusual parent process name on Windows.
sigmaWindowsmedium2017-08-15