Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Detect Cmd.exe Redirection of Discovery Commands by Ursnif
Flags explorer-launched cmd.exe commands that use /C and redirect output to AppData local temp .bin files.
sigmahigh2023-07-16Windows PowerShell WMI Win32_NTEventlogFile Calls with Event Log Tampering Methods
Flags PowerShell calling Win32_NTEventlogFile WMI methods commonly used to clear, delete, backup, or alter Windows event logs.
sigmaWindowshigh2023-07-13Windows Security 5140 File Share Access to MSHTML_C7 IP-Named Paths
Alerts on Windows file share access events targeting \MSHTML_C7\ shares with an IP-like naming pattern (EventID 5140).
sigmahigh2023-07-13Windows Process Creation From Fake Recycle.Bin Directories
Alerts on Windows processes launched from fake RECYCLER.BIN / RECYCLERS.BIN folder paths often used for stealth.
sigmaWindowshigh2023-07-12Windows: Suspicious File Creation in Fake RECYCLER.BIN Staging Folders
Alerts on Windows file writes involving RECYCLERS.BIN\ or RECYCLER.BIN\ paths often used for staging.
sigmaWindowshigh2023-07-12HTTP GET Requests Containing /MSHTML_C7/ URL Marker (Proxy Logs)
Alerts on proxy HTTP GET requests whose URI contains /MSHTML_C7/.
sigmahigh2023-07-12Proxy GET Requests with IP-Embedded CVE-Related URL Parameters
Finds proxy GET URIs with risky extensions and a d=IPv4 parameter value in the query string.
sigmahigh2023-07-12Windows DLL Sideloading via Abusable DLLs Loaded from Suspicious Locations
Flags Windows module loads of specific abusable DLL names from public, temp, or user folders consistent with potential DLL sideloading.
sigmaWindowshigh2023-07-11Windows PowerShell Decryption-Like Activity Involving .LNK File Processing
Identifies PowerShell runs that enumerate and process *.lnk content using byte-level reads/writes consistent with decryption staging.
sigmaWindowshigh2023-06-30Windows Registry: Uncommon Microsoft Office Trusted Location Path Added
Alerts on registry changes adding non-standard Microsoft Office Trusted Location paths that could undermine macro security.
sigmaWindowshigh2023-06-21Windows Registry TrustRecords Change for Macro-Enabled Documents in Suspicious Paths
Alert on Windows registry changes to Office TrustRecords where trusted-document paths fall in suspicious directories.
sigmaWindowshigh2023-06-21Windows: Office Executable Running a Document from Trusted Template/Startup Paths
Alerts when Office apps are launched with command lines pointing to documents under Office template/Startup paths.
sigmaWindowshigh2023-06-21Windows DLL side-loading via appverifUI.dll image loads
Alerts when appverifUI.dll is loaded on Windows from unexpected paths, a common DLL sideloading technique.
sigmaWindowshigh2023-06-20Windows Security 4719: Important Audit Policy Categories Disabled
Alerts on Windows Security 4719 indicating auditing was disabled for important security event subcategories.
sigmaWindowshigh2023-06-20Linux Process Creation: wget Download Tar From Untrusted Direct IP with No-Check-Certificate
Flags wget commands that download .tar files from direct IP URLs while bypassing TLS certificate validation.
sigmahigh2023-06-16Linux Process: Wget Downloads .zip/.rar from temp.sh URL
Identifies Linux wget commands that download .zip or .rar archives from temp.sh.
sigmahigh2023-06-16Linux openssl s_client Connections to External IPs for SSL Certificate Exfiltration
Detects openssl s_client connecting to an IP:port on 443/8080 from Linux process command lines.
sigmahigh2023-06-16Linux File Indicators Matching Suspected Barracuda ESG Exploitation Artifacts
Flags Linux file creation/access events whose filenames end with known Barracuda ESG exploitation artifact indicators.
sigmahigh2023-06-16Linux Email Exfiltration Staging File Pattern Matching (/mail/tmp/**.tar.gz)
Flags Linux file events creating /mail/tmp staging archives named like abc123.tar.gz.
sigmahigh2023-06-16Windows VMwareToolBoxCmd.exe Script/Set Execution Used for VM State Persistence
Alerts on VMwareToolBoxCmd.exe launched with script/set flags and command-line hints of a suspicious VM state persistence setup.
sigmaWindowshigh2023-06-14