Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
90 rules
Windows Process Creation: mshta/VBScript Launching PowerShell and Embedded Backdoor Logic
Alerts on Windows command lines combining mshta VBScript execution bypass, system survey WMI queries, and PowerShell HTTP/Base64 patterns.
sigmahigh2023-03-10Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
sigmaWindowshigh2023-03-08Windows WMIC Remote Query Execution via /node
Identifies remote WMIC queries on Windows by matching WMIC execution with /node: in the command line.
sigmaWindowsmedium2023-02-14Windows WMIC.exe Service Reconnaissance via Remote Service Queries
Flags WMIC.exe commands containing service-related reconnaissance strings while excluding stop/start service manipulation.
sigmaWindowsmedium2023-02-14Windows WMIC.exe Product Class Reconnaissance via Security Product Queries
Detects wmic.exe being used to enumerate firewall, antivirus, and antispyware product classes.
sigmaWindowsmedium2023-02-14Windows WMIC Product Reconnaissance via Firewall/AV Enumeration
Alerts on wmic.exe executions with command lines consistent with Windows product enumeration for reconnaissance.
sigmaWindowsmedium2023-02-14Windows wmic.exe Hardware Model Reconnaissance Using csproduct
Flags wmic.exe executions that include "csproduct" to query hardware model/vendor details.
sigmaWindowsmedium2023-02-14Windows PowerShell Base64-Encoded WMI Class Invocation
Flags PowerShell command lines containing Base64 fragments indicative of WMI class usage (e.g., ShadowCopy, ScheduledJob) on Windows.
sigmaWindowshigh2023-01-30Windows WMIC System Information Discovery via WMIC.EXE Recon
Flags WMIC.EXE executions running system info queries for OS and disk details.
sigmaWindowsmedium2023-01-26Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
sigmaWindowshigh2023-01-18Windows DLL Sideloading: WmiApSrv Loads VMGuestLib.dll
Flags WmiApSrv.exe loading VMGuestLib.dll from VMware Tools vmStatsProvider on Windows.
sigmaWindowsmedium2022-12-01Windows PowerShell WMI Volume Shadow Copy Deletion
Flags PowerShell WMI/CIM commands that query Win32_ShadowCopy and attempt deletion.
sigmaWindowshigh2022-09-20PowerShell WMI Script Deletes Windows Volume Shadow Copies
Flags PowerShell WMI/CIM scripts that enumerate Win32_ShadowCopy and attempt to delete it.
sigmaWindowshigh2022-09-20Windows WMIC System Reconnaissance Using "computersystem" Flag
Flags wmic.exe runs that include the "computersystem" argument for Windows host information discovery.
sigmaWindowsmedium2022-09-08Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.
sigmaWindowshigh2022-09-01Windows: Detect Suspicious mofcomp.exe Execution from Scripts or Temp Paths
Flags mofcomp.exe runs spawned by script interpreters or using temp/AppData paths, with exclusions for WmiPrvSE .mof-related activity.
sigmaWindowshigh2022-07-12Windows wmic.exe Used to Start or Stop Services
Alerts on wmic.exe command lines invoking startservice or stopservice via service calls.
sigmaWindowsmedium2022-06-20Windows WMIC Process Creation Recon for Unquoted Service Paths
Flags wmic.exe service queries requesting name/displayname/pathname/startmode to support unquoted service path reconnaissance.
sigmaWindowsmedium2022-06-20Windows Hotfix Inventory Recon via wmic.exe qfe
Detects wmic.exe executions with "qfe" used to enumerate installed Windows hotfixes.
sigmaWindowsmedium2022-06-20PowerShell WMI Service Enumeration for Unquoted Service Path Recon
Flags PowerShell WMI queries for Win32_Service fields to enumerate potential unquoted service path issues.
sigmaWindowsmedium2022-06-20