Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
528 rules
PowerShell VBScript RegWrite Registry Modification Attempts
Identifies PowerShell commands embedding VBScript Wscript.shell .RegWrite to modify Windows registry values.
sigmaWindowsmedium2025-08-13Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.
sigmahigh2025-08-01Windows Suspicious File Writes to SharePoint Web Server Extensions Layouts Directory
Alerts on cmd/powershell/w3wp writes of script or web asset files into SharePoint layouts (15/16 TEMPLATE/ LAYOUTS).
sigmaWindowshigh2025-07-24Windows PowerShell sets Microsoft Defender threat severity default actions to Allow/NoAction
Alerts when PowerShell Set-MpPreference sets Defender threat-severity default actions to Allow or NoAction.
sigmaWindowshigh2025-07-11Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell
Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.
sigmaWindowshigh2025-07-09Windows Process Information Discovery via Registry Queries (reg.exe/powershell)
Flags reg.exe and PowerShell registry queries used to enumerate OS, Defender, installed apps, timezone, and services.
sigmaWindowslow2025-06-12Windows PowerShell Obfuscated COM MSI Installation via WindowsInstaller.Installer
PowerShell spawning that uses WindowsInstaller.Installer COM with obfuscated strings to call InstallProduct and suppress UI.
sigmaWindowshigh2025-05-27Windows: New-ADServiceAccount Creates Delegated Service Account in Target OUs
Alerts on PowerShell runs of New-ADServiceAccount to create a delegated service account with -CreateDelegatedServiceAccount and -path.
sigmaWindowsmedium2025-05-24Windows PowerShell Modifies dMSA msDS-ManagedAccountPrecededByLink Attributes
Flags PowerShell script content modifying msDS-ManagedAccountPrecededByLink (dMSA link attributes) via AD link changes.
sigmaWindowslow2025-05-24PowerShell dMSA Service Account Creation in Target OUs via New-ADServiceAccount
Alerts on PowerShell creating a delegated service account via New-ADServiceAccount with -CreateDelegatedServiceAccount and -path.
sigmaWindowsmedium2025-05-24Windows: Suspicious child processes spawned by CrushFTP service
Alerts when CrushFTP service (crushftpservice.exe) launches shell/script executables like PowerShell, cmd, mshta, or bash.
sigmamedium2025-04-10Windows Process Creation: Disabling Security Logging via MiniNt Registry Key Set
Flags reg.exe or PowerShell commands that create/modify the MiniNt registry key to impair Windows event logging.
sigmaWindowshigh2025-04-09Windows PowerShell History File Access Attempt via ConsoleHost_history.txt
Alerts on Windows process executions whose command line references PowerShell console history files or HistorySavePath.
sigmaWindowsmedium2025-04-03Windows PowerShell ScriptBlock: Get-ADComputer reconnaissance for unconstrained delegation properties
Flags PowerShell script blocks that query AD computer delegation-related properties using Get-ADComputer-style discovery.
sigmaWindowsmedium2025-03-05Windows Scheduled Task Creation via schtasks.exe with curl and PowerShell Command Line Indicators
Alerts on schtasks.exe task creation commands that simultaneously include curl download indicators and PowerShell execution.
sigmaWindowsmedium2025-02-05Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Flags conhost.exe spawning command/scripting utilities like PowerShell, MSHTA, or regsvr32.exe.
sigmaWindowshigh2025-02-05Windows Process Creation: Suspicious cmd.exe Launch with Encoded PowerShell from Cleo Suite
Alerts on cmd.exe launching PowerShell encoded commands from Cleo javaw.exe components with .Download.
sigmahigh2024-12-09Windows Registry RunMRU PowerShell or WMIC Execution Command Indicators
Alerts on RunMRU registry entries showing PowerShell (encoding/invocation) or WMIC shadowcopy/process call usage.
sigmaWindowshigh2024-11-01Windows MeshAgent remote command execution via cmd.exe or PowerShell child processes
Flags cmd.exe or PowerShell spawned by meshagent.exe on Windows, indicating potential remote command execution.
sigmaWindowsmedium2024-09-22Windows DISM Enables PowerShell Web Access Feature via Command Line
Flags DISM executions that enable the WindowsPowerShellWebAccess feature using /online and /enable-feature parameters.
sigmaWindowshigh2024-09-03