Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows DLL Sideloading: waveedit.dll Loaded by Nero WaveEditor
Alerts when waveedit.dll is loaded from an unexpected path, suggesting possible DLL sideloading on Windows.
sigmaWindowshigh2023-06-14Potential GeoServer SQLi Probe for CVE-2023-25157 via OWS CQL_FILTER
Alerts on GET requests to GeoServer OWS with CQL_FILTER containing SQLi-style payload markers and functions.
sigmahigh2023-06-14dfsvc.exe Initiated Network Connection to Uncommon Ports (Windows)
Alerts on dfsvc.exe-initiated outbound connections targeting non-standard ports on Windows, excluding typical 80/443 and IPv6 DNS(53).
sigmahigh2023-06-12Windows: Potential RjvPlatform.dll DLL Sideloading via SystemResetPlatform.exe from Non-Default Path
Flags SystemResetPlatform.exe loading RjvPlatform.dll from a non-default location, indicating possible DLL sideloading.
sigmaWindowshigh2023-06-09Windows DLL Sideloading Suspicion via edputil.dll Image Load
Alerts on edputil.dll image loads occurring outside standard Windows system directories, suggesting possible DLL side-loading.
sigmaWindowshigh2023-06-09Windows Registry COM InProcServer32 Hijack via PSFactory CLSID Default Value
Detects suspicious modifications to a PSFactory COM InProcServer32 (Default) registry value that may enable COM-based persistence.
sigmaWindowshigh2023-06-07Windows Code Integrity: Kernel Module Loaded Without WHQL Requirements (Event 3082/3083)
Alerts when Code Integrity logs show loaded kernel modules failing WHQL compliance (Event 3082/3083), excluding selected VMware drivers.
sigmaWindowshigh2023-06-06Windows Code Integrity Operational: Unsigned Image Loaded
Alerts on Windows Code Integrity detecting that an unsigned image was loaded (Event ID 3037).
sigmaWindowshigh2023-06-06Windows Code Integrity Unsigned Kernel Module Loaded (Event ID 3001)
Alerts on Windows Code Integrity reporting an unsigned kernel module load via Event ID 3001.
sigmaWindowshigh2023-06-06Windows Code Integrity: Revoked Signed Image Loaded (Event 3032/3035)
Alerts on Code Integrity events showing a revoked signed image was loaded, including debugger-allowed cases.
sigmaWindowshigh2023-06-06Windows Code Integrity blocks image load when signing certificate is revoked (Event ID 3036)
Alerts on Windows Code Integrity Event ID 3036 when image loads are blocked because the signing certificate is revoked.
sigmaWindowshigh2023-06-06Windows Code Integrity: Revoked Kernel Driver Loaded (Event 3021/3022)
Alerts when Windows Code Integrity reports a revoked kernel driver/module loaded (including debugger-allowed cases) via Event IDs 3021/3022.
sigmaWindowshigh2023-06-06Windows Code Integrity: Blocked Driver Load Due to Revoked Certificate (Event ID 3023)
Flags Code Integrity Operational events where Windows blocks loading a revoked (untrusted) driver certificate.
sigmaWindowshigh2023-06-06Windows Code Integrity blocked disallowed file for protected processes (Event ID 3104)
Alerts on Windows Code Integrity Event ID 3104 when a disallowed file is blocked for protected processes.
sigmaWindowshigh2023-06-06Windows Process Creation: Renamed AutoIt2/AutoIt3 Execution via AutoIt3ExecuteScript
Alerts on suspicious renamed AutoIt2/AutoIt3 execution based on command-line parameters plus known hashes and original file names.
sigmaWindowshigh2023-06-04Webserver GET Requests to MOVEit Human2.aspx Paths Indicative of CVE-2023-34362 Web Shell Attempts
Alerts on GET requests to human2.aspx/_human2.aspx paths associated with MOVEit CVE-2023-34362 exploitation attempts.
sigmahigh2023-06-03Linux: Shell Execution from /tmp by Parent Process
Alert when a /tmp parent process spawns a shell (bash/sh/zsh/etc.), indicating likely staging and command execution.
sigmaLinuxhigh2023-06-02Linux nohup Execution from /tmp
Flags Linux process executions using nohup with command lines referencing /tmp.
sigmaLinuxhigh2023-06-02Linux grep file discovery targeting GobRAT-specific filenames
Alerts on grep executions on Linux whose arguments contain specific malware-related file names for discovery.
sigmaLinuxhigh2023-06-02Windows DLL Sideloading via SmadHook32c.dll and SmadHook64c.dll Loads
Alerts on non-standard loads of SmadHook32c.dll/SmadHook64c.dll on Windows, consistent with potential DLL sideloading.
sigmaWindowshigh2023-06-01