Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
Windows Process Creation: svchost.exe with msupdate/alg Service Flags
Alerts on svchost.exe started with specific -k command-line flags consistent with suspicious persistence activity.
sigmacritical2023-04-30Windows rundll32 Cleanup Export Execution via msupdate Service Host (ColdSteel)
Flags svchost.exe msupdate-style services spawning rundll32.exe to run cleanup-related exports.
sigmacritical2023-04-30Windows: Detect suspicious PowerShell/Lsass tool execution launched by ManageEngine (ServiceDesk)
Alerts on suspicious child PowerShell/LSASS/tool activity launched by ManageEngine ServiceDesk (Java parent) on Windows.
sigmacritical2023-04-20Windows Process Creation: AsperaFaspex Parent Spawning PowerShell or Credential-Access Tooling
Detects AsperaFaspex (aspera\ruby parent) spawning suspicious PowerShell, LSASS, web download, privilege, or defensive-evasion commands on Windows.
sigmacritical2023-04-20Windows: Rorschach execution indicator via critical command-line pattern
Windows process creation events with certain system utilities and a "11111111" command-line marker are flagged as ransomware execution activity.
sigmacritical2023-04-04Windows DLL Image Load Identified by Hashes for Compromised 3CXDesktopApp Components
Flags DLL loads in Windows when loaded module hashes match known compromised 3CXDesktopApp-related files.
sigmacritical2023-03-31Windows: Outlook querying WebClient/LanmanWorkstation registry network provider keys
Flags Outlook.exe querying HKLM\SYSTEM\Services WebClient/LanmanWorkstation NetworkProvider registry values.
sigmacritical2023-03-16Windows Process Execution Matches Griffon Malicious Command-Line Pattern
Alerts on Windows process command lines containing a temp staging path plus jscript execution indicators and a .txt target.
sigmacritical2023-03-09Windows DNS Client: Cobalt Strike DNS Beaconing Patterns via Suspicious Query Names
Alerts when Windows DNS client logs show Event ID 3008 DNS queries matching Cobalt Strike beacon patterns.
sigmaWindowscritical2023-01-16Webserver: OWASSRF exploitation attempt via OWA to PowerShell backend
Flags webserver POSTs returning 200 that request both /owa/mastermailbox and /powershell, consistent with OWASSRF exploitation attempts.
sigmacritical2022-12-22Detects OWASSRF Proxy Exploitation Attempt via OWA to PowerShell Backend
Identifies proxy POSTs that return 200 and request both /owa/mastermailbox and /powershell, indicating potential OWASSRF exploitation.
sigmacritical2022-12-22Windows Process Creation: SysmonEOP.exe HackTool Execution (CVE-2022-41120 PoC)
Alert on Windows process execution of \SysmonEOP.exe with specific IMPhashes associated with the SysmonEOP PoC.
sigmaWindowscritical2022-12-04Inveigh Execution via Process Creation (Windows)
Detects execution of Inveigh.exe on Windows with spoofing/sniffing command-line flags consistent with MITM behavior.
sigmaWindowscritical2022-10-24Windows Inveigh HackTool Execution Artefacts via Inveigh File Indicators
Alert on Windows file creation or presence of Inveigh log, script, and binary artefacts identified by distinctive filename suffixes.
sigmaWindowscritical2022-10-24Windows Process Execution: SafetyKatz HackTool (SafetyKatz.exe)
Alerts when a process running SafetyKatz.exe is created, using image path and embedded file metadata.
sigmaWindowscritical2022-10-20Windows Security: Suspicious SAMTHEADMIN-* Computer/Account Names Ending with $
Alerts on Windows Security events with computer account names starting SAMTHEADMIN- and ending with $.
sigmaWindowscritical2022-09-09Windows process command line matching Sliver C2 implant NoExit PowerShell UTF8 pattern
Alerts on Windows process command lines matching a Sliver-style PowerShell -NoExit encoding pattern.
sigmaWindowscritical2022-08-25Windows: SharpUp (SharpUp.exe) Local Privilege Escalation Tool Execution
Flags SharpUp.exe execution on Windows when command line indicators reference common privilege-escalation targets.
sigmaWindowscritical2022-08-20Windows named pipe creation matching DiagTrackEoP POC pipe name fragment
Flags Windows creation of a named pipe matching the DiagTrackEoP POC’s default pipe name.
sigmaWindowscritical2022-08-03Windows Security: DiagTrackEoP POC Default UserName Login Attempt (LogonType 9)
Alerts on Windows 4624 LogonType 9 events targeting a known DiagTrackEoP default username.
sigmaWindowscritical2022-08-03