Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Linux Process Creation Indicators for LiteLLM Backdoored Package Activity (v1.82.7/v1.82.8)
Identifies Linux process executions matching indicators tied to backdoored LiteLLM v1.82.7/v1.82.8 credential-stealer and persistence activity.
sigmahigh2026-03-30Linux Persistence File Creation Targeting sysmon.py and systemd user service
Alerts on creation of user persistence files under sysmon.py or systemd user service paths by a process running from /python3.
sigmahigh2026-03-30Windows: Detect NetExec (nxc.exe) Process Execution with Network Service Commands
Flags Windows execution of NetExec (nxc.exe) when command lines include SMB/RDP/SSH/WinRM/WMI and other protocol keywords.
sigmaWindowshigh2026-03-29Windows Process Creation: curl Uploads to File-Sharing Domains
Detects curl commands on Windows uploading files to common file sharing/upload domains.
sigmaWindowshigh2026-03-29Windows System Restore Registry Modification via PowerShell or reg.exe Command Line
Flags PowerShell/reg.exe command lines modifying Windows System Restore registry keys to disable or restrict recovery.
sigmaWindowshigh2026-03-11Windows Process Creation: Python One-Liners Decoding Base64 via Command Line
Alerts on Windows Python command-line one-liners that import base64 and call decode functions.
sigmaWindowshigh2026-03-09Linux Process Execution of Python Base64 Decode One-Liners
Alerts on Linux process creations running Python -c one-liners that import base64 and invoke decoding functions.
sigmaLinuxhigh2026-03-09Windows: Suspicious Child Command Execution by SolarWinds WebHelpDesk (WHD)
Alerts on WebHelpDesk (bin) spawning tool-like child processes with download/execution command patterns on Windows.
sigmahigh2026-02-11Windows: Suspicious Child Process Execution by Notepad++ Updater (gup.exe)
Alerts when Notepad++ gup.exe spawns command/scripting or utility processes using suspicious tool keywords on Windows.
sigmaWindowshigh2026-02-03Windows File Creation by Notepad++ Updater gup.exe in Uncommon Locations
Alerts on file creations by Notepad++ updater gup.exe when the destination path is uncommon or not in allowed locations.
sigmaWindowshigh2026-02-03Windows Vulnerable Driver Blocklist Disabled via Registry DWORD Setting
Flags registry changes that disable Windows Vulnerable Driver Blocklist (VulnerableDriverBlocklistEnable = 0).
sigmaWindowshigh2026-01-26Windows Vulnerable Driver Blocklist Registry Tampering via PowerShell or REG.EXE
Flags PowerShell/REG.EXE command lines that change the VulnerableDriverBlocklistEnable registry setting under \Control\CI\Config.
sigmaWindowshigh2026-01-26Windows HVCI Registry Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/pwsh or reg.exe command lines modifying HVCI/Hypervisor-enforced code integrity registry values.
sigmaWindowshigh2026-01-26Windows Registry Modification: OracleOciLib/OracleOciLibPath Under MSDTC for oci.dll Redirection
Alerts on MSDTC MTxOCI registry changes to OracleOciLib/OracleOciLibPath that may redirect oci.dll loading to attacker-controlled locations.
sigmaWindowshigh2026-01-24OpenCanary RDP New Connection Attempt on Application Logtype 14001
Alerts on OpenCanary logging a new RDP connection attempt (logtype 14001), indicating remote access probing.
sigmahigh2026-01-06OpenCanary Application Logs: Detect SYN Port Scan Targets on a Hosted Node
Flags OpenCanary events indicating the host was probed with a TCP SYN port scan.
sigmahigh2026-01-06OpenCanary application logs: detect NMAP XMAS scans targeting an OpenCanary node
Detects OpenCanary log events showing an Nmap Xmas scan targeting the monitored node.
sigmahigh2026-01-06OpenCanary: Detect NMAP OS Scan Targets via Application Logtype 5002
Alerts when OpenCanary records an NMAP OS scan event (logtype 5002), indicating host fingerprinting activity.
sigmahigh2026-01-06OpenCanary - Nmap NULL Scan Targeting Detected
Detects OpenCanary logtype 5003 events consistent with NMAP NULL scan targeting.
sigmahigh2026-01-06OpenCanary Application Logs: Nmap FIN Scan Targeting (Logtype 5005)
Detects Nmap FIN scan targeting against an OpenCanary node using application logs with logtype 5005.
sigmahigh2026-01-06