Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
AWS CloudTrail: S3 Browser creates inline IAM policy with default bucket placeholder
Detects S3 Browser–initiated IAM PutUserPolicy requests that include a templated S3 bucket placeholder in the inline policy.
sigmaCloudhigh2023-05-17AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile
Flags CloudTrail IAM GetLoginProfile and CreateLoginProfile activity initiated by an S3 Browser user agent.
sigmaCloudhigh2023-05-17Windows LiveKD Kernel Memory Dump Attempt via "-m" Flag
Flags LiveKD executions with the "-m" option that may trigger kernel memory dumping on Windows.
sigmaWindowshigh2023-05-16Windows LiveKD Driver File Creation by Uncommon Process Image
Alerts when LiveKdD.SYS is created by a process other than livekd.exe/livek64.exe on Windows.
sigmaWindowshigh2023-05-16Windows: LiveKD kernel memory dump file creation (livekd.dmp)
Flags creation of C:\Windows\livekd.dmp, a default LiveKD kernel memory dump file name.
sigmaWindowshigh2023-05-16Proxy Web Requests Matching Devil Bait C2 HTTP Parameters
Identifies proxy HTTP GET requests to /cross.php containing op, dt, and uid query parameters consistent with potential C2 traffic.
sigmahigh2023-05-15Windows Wscript/Cscript Executes Files with Uncommon Non-Script Extensions
Flags wscript.exe/cscript.exe launching files named with uncommon non-script extensions via command-line content.
sigmaWindowshigh2023-05-15Suspicious Child Process of GoogleUpdate.exe on Windows
Alerts when GoogleUpdate.exe spawns an unexpected child process on Windows, using parent/child image telemetry and allowlisting common Google updaters.
sigmaWindowshigh2023-05-15Windows Process Creation: certutil.exe Encodes Files to Base64 in Suspicious Paths
Alert on certutil.exe running with -encode when the command line references files under suspicious directories.
sigmaWindowshigh2023-05-15Windows: certutil.exe Encodes Files to Base64 Using -encode With Suspicious Extensions
Alert on certutil.exe -encode activity that targets files with suspicious extensions.
sigmaWindowshigh2023-05-15Windows Process Creation: SolidPDFCreator.dll Copy and Run Key Persistence Indicators
Flags Windows command lines that copy SolidPDFCreator.dll and set a Run registry key for auto-execution.
sigmahigh2023-05-15Windows: GoogleUpdate.exe Self-Spawn From Uncommon Path
Alerts when GoogleUpdate.exe launches another GoogleUpdate.exe from an unusual directory.
sigmahigh2023-05-15Windows Devil Bait-like Recon via Wscript/Cmd with APPDATA Redirection
Flags cmd.exe launched by wscript.exe to redirect discovery output into %APPDATA%\Microsoft (.xml/.txt) using system enumeration commands.
sigmahigh2023-05-15Uncommon Windows Processes Writing .txt/.xml in AppData\Roaming\Microsoft
Flags creation of .txt/.xml files in AppData\Roaming\Microsoft by schtasks.exe, wscript.exe, or mshta.exe.
sigmahigh2023-05-15Potential C2 HTTP Traffic via Goofy Guineapig User-Agent to static.tcplog.com (Proxy Logs)
Flags proxy HTTP requests with a specific Chrome-like User-Agent to static.tcplog.com, consistent with potential C2 traffic.
sigmahigh2023-05-14Windows Process Command Line Matching Goofy-Guineapig Backdoor Command Fragment
Alerts on Windows process command lines containing a specific non-interactive choice command often used in automation.
sigmahigh2023-05-14Windows File Indicators for Goofy Guineapig Malware IOCS
Flags Windows file events involving specific Goofy Guineapig backdoor indicator filenames.
sigmahigh2023-05-14Windows Registry Events Targeting SECURITY\Policy\Secrets\ (Snake Malware)
Alerts on Windows registry activity targeting the SECURITY\Policy\Secrets\n registry key suffix.
sigmahigh2023-05-11Windows File Creation: Non-System WerFault.exe Created in WinSxS
Flags creation of C:\Windows\WinSxS\WerFault.exe by processes outside core Windows system directories.
sigmahigh2023-05-10PowerShell ScriptBlock Function Get-VMRemoteFXPhysicalVideoAdapter Module Creation
Flags PowerShell module content that defines Get-VMRemoteFXPhysicalVideoAdapter in a ScriptBlock, consistent with load-order abuse patterns.
sigmaWindowshigh2023-05-09