Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Windows Process Execution of JavaScript via Node.exe
Alerts when node.exe starts a process with a .js argument on Windows, which may indicate suspicious script execution.
sigmaWindowslow2025-04-21Windows: Notepad Password File Discovery via Process Creation
Flags explorer-launched Notepad opening files named like password*.{txt,csv,doc,xls} that may contain credentials.
sigmaWindowslow2025-02-21Windows Process Creation: Microsoft QuickAssist.exe Execution
Alerts on execution of QuickAssist.exe by matching the process image ending with \QuickAssist.exe.
sigmaWindowslow2024-12-19Windows DNS Queries Initiated by QuickAssist.exe to remoteassistance.support.services.microsoft.com
Alerts when QuickAssist.exe performs DNS lookups for the Microsoft Quick Assist remote session endpoint.
sigmaWindowslow2024-12-19Windows Command Execution via Run Dialog (RunMRU) Registry Entries
Flags suspicious Run dialog command entries by matching RunMRU registry key updates on Windows.
sigmalow2024-11-01Windows Security 4663: Uncommon Processes Access Browser Credential Store Files
Flags 4663 file access to browser credential stores (Chromium/Firefox) by processes outside common system/benign paths.
sigmalow2024-10-21Windows IIS module removal event (IIS-configuration EventID 29)
Detects removal of an IIS module from Windows IIS configuration events (Event ID 29).
sigmaWindowslow2024-10-06Windows Task Scheduler DLL Loaded From Uncommon Directory
Flags taskschd.dll being loaded by a process from Temp/public/user directories commonly abused for malicious activity.
sigmalow2024-09-02Windows Cmd.exe: SET /p file append/override pattern via set /p=
Alerts on Cmd.exe command lines containing SET /p= syntax that may be used with redirection to modify file contents.
sigmalow2024-08-22Windows Registry Set Internet Settings ZoneMap Proxy and Intranet Values
Alerts on Windows ZoneMap registry changes that set proxy/intranet bypass values, using registry set-value telemetry and process image context.
sigmalow2024-07-31Windows: Uncommon Process Access to Chromium User Data Cookies and History
Alerts on uncommon executables reading Chromium cookies/history/web data on Windows, excluding common system and installer paths.
sigmalow2024-07-29Windows File Access Attempt to Panther\unattend.xml During Unattended Install
Alerts on attempts to access Panther\unattend.xml on Windows, a potential source of embedded credentials.
sigmalow2024-07-22Windows Process Execution of BitLockerToGo.EXE
Alerts on Windows execution of BitLockerToGo.exe, a rarely used BitLocker To Go component for portable drive encryption.
sigmaWindowslow2024-07-11AWS CloudTrail: CreateNetworkAclEntry Adds Network ACL Rules
Identifies when EC2 network ACL entries are created in AWS via CloudTrail.
sigmaCloudlow2024-07-11Windows: Microsoft Word Loads WLL Add-In Files
Flags Microsoft Word loading a .wll add-in module on Windows using image load telemetry.
sigmalow2024-07-10Windows Process Access to Uncommon Target Images Using PROCESS_ALL_ACCESS
Alerts on Windows events granting PROCESS_ALL_ACCESS to processes with uncommon target image filenames.
sigmaWindowslow2024-05-27Windows PowerShell ScriptBlock Adds Allow Firewall Rule via New-NetFirewallRule
Flags PowerShell ScriptBlock text that invokes New-NetFirewallRule to add an Allow firewall rule.
sigmalow2024-05-10Unusual Access to Windows Outlook Unistore Mail Data by Non-Standard Processes
Alerts when unusual processes access Outlook Unistore (data and UnistoreDB store.vol) file locations on Windows.
sigmalow2024-05-10PowerShell New-NetFirewallRule Adds Windows Allow Firewall Rule
Alert on PowerShell creating a new Windows firewall rule that sets the action to Allow via New-NetFirewallRule.
sigmalow2024-05-03Kubernetes API Audit: Unauthorized (401) or Forbidden (403) Access Attempts
Alerts on Kubernetes API audit events returning 401 or 403, indicating authentication or authorization failures.
sigmalow2024-04-12