Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
528 rules
Non-privileged reg.exe or PowerShell registry service configuration changes on Windows
Flags non-admin reg.exe or PowerShell activity targeting service registry configuration paths on Windows.
sigmaWindowshigh2020-10-05Windows: SyncAppvPublishingServer.exe execution via PowerShell script block content
Flags PowerShell script blocks that reference SyncAppvPublishingServer.exe, indicating possible execution via a PowerShell-restricted workflow.
sigmaWindowsmedium2020-10-05Windows SyncAppvPublishingServer Execution Triggering PowerShell Module Context
Alerts when SyncAppvPublishingServer.exe appears in PowerShell module ContextInfo on Windows.
sigmaWindowsmedium2020-10-05Windows Security: Suspicious Remote Logon Using Explicit Credentials via Command-Line Tools
Flags EventID 4648 remote logons initiated by cmd/PowerShell/winrs/wmic/net/reg-style processes using explicit credentials.
sigmaWindowsmedium2020-10-05Windows Process Proxying: explorer.exe Spawned from cmd.exe or PowerShell
Flags cmd.exe/powershell.exe launching explorer.exe, indicating possible proxy-based execution on Windows.
sigmalow2020-10-05Windows PowerShell Command Lines Containing [char]0x or (WCHAR)0x Obfuscation Syntax
Identifies PowerShell execution command lines using suspicious [char]0x or (WCHAR)0x encoding patterns.
sigmaWindowshigh2020-07-09Windows Process Execution: Copy From System Directories to Other Locations
Detects cmd.exe, PowerShell, and copy utilities copying files from System32/SysWOW64/WinSxS to other locations on disk.
sigmaWindowsmedium2020-07-03PowerShell Classic bXOR Operator Usage in Command Line
Identifies PowerShell classic executions from ConsoleHost using the -bxor operator in the command line.
sigmalow2020-06-29Suspicious WSMAN COM Provider Usage Without PowerShell Host (Windows)
Alerts on WSMAN COM provider activity where the host application is not PowerShell.exe in PowerShell Classic logs.
sigmaWindowsmedium2020-06-24Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Identifies Windows PowerShell command lines commonly used by Covenant launchers, including hidden/encoded execution patterns.
sigmaWindowshigh2020-06-04Windows: CrackMapExec PowerShell obfuscation via join/split static patterns
Flags Windows PowerShell executions with command-line obfuscation strings associated with CrackMapExec behavior.
sigmaWindowshigh2020-05-22Windows: Process executions matching Greenbug espionage tool indicators
Alerts on Windows process creation with command-line patterns matching PowerShell execution-policy bypass and reverse-shell related tooling.
sigmacritical2020-05-20PowerShell Get-Clipboard Cmdlet Execution via CLI on Windows
Flags Windows command lines containing Get-Clipboard, indicating potential clipboard data collection via PowerShell.
sigmaWindowsmedium2020-05-02Windows PowerShell Get-Clipboard Command Execution
Flags PowerShell activity that includes the Get-Clipboard command, which may be used to collect clipboard contents.
sigmaWindowsmedium2020-05-02PowerShell Decompress via Expand-Archive
Alerts on PowerShell usage of Expand-Archive, a common decompression step attackers may use to unpack files.
sigmaWindowsinformational2020-05-02PowerShell Local User Creation via New-LocalUser
Flags PowerShell usage of New-LocalUser, indicating creation of a Windows local user.
sigmaWindowsmedium2020-04-11Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Flags HH.exe spawning CertReq/CertUtil/CMD/PowerShell/cscript/regsvr32/mshta and other common Windows execution utilities.
sigmaWindowshigh2020-04-01Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
sigmaWindowshigh2020-03-26Windows PowerShell execution with uncommon/suspicious parent process
Alerts when PowerShell is started from certain unusual parent processes that commonly indicate abuse.
sigmaWindowshigh2020-03-20PowerShell Downgrade Attempts via -Version 2 on Windows Process Creation
Alerts on PowerShell executions specifying a -Version 2 argument, consistent with potential downgrade attempts.
sigmaWindowsmedium2020-03-20