Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Okta FastPass blocks phishing authentication attempts via MFA
Alerts on Okta FastPass MFA failures where the declined reason indicates a known phishing attempt.
sigmaIdentityhigh2023-05-07Windows Wget.exe Downloads From File-Sharing Domains Matching Suspicious Output Flags
Flags wget.exe executions on Windows that download via HTTP from known file-sharing domains and write specific file extensions to disk.
sigmaWindowshigh2023-05-05Windows curl.exe Downloads from File-Sharing Domains with Suspicious Output Extensions
Alerts on curl.exe downloading files over HTTP from file-sharing/content hosting domains, based on process command-line and executable context.
sigmaWindowshigh2023-05-05Windows: Process Explorer Driver (.sys) Creation by Non-Process Explorer Process
Alerts on creation of PROCEXP-named .sys drivers by processes other than Process Explorer.
sigmaWindowshigh2023-05-05Windows PowerShell Credential Dumping Script Targeting Veeam Backup ProtectedStorage
Alerts on PowerShell scripts that reference Veeam protected storage and credential extraction indicators, enabling stored credential dumping on Windows.
sigmaWindowshigh2023-05-04Windows PowerShell Script Block Matching POWERTRASH Behavior Indicators
Detects PowerShell ScriptBlock text containing POWERTRASH-related in-memory and dynamic execution indicators on Windows.
sigmahigh2023-05-04PowerShell ScriptBlock Launching wscript.exe via PowerHold-like Code Patterns on Windows
Flags PowerShell ScriptBlock text that writes staged bytes in APPDATA and launches wscript.exe.
sigmahigh2023-05-04Windows PowerShell Script File Creation Matching FIN7-Style Filenames
Alerts on Windows PowerShell script drops named host_ip.ps1 or ending with _64refl.ps1.
sigmahigh2023-05-04Windows process execution: WerFault.exe launched from WinSxS by services.exe
Alerts on WerFault.exe running from WinSxS when spawned by services.exe on Windows.
sigmahigh2023-05-04Windows Process Creation: Detect jpinst.exe/jpsetup.exe Installation Binary Indicators
Detects execution of jpinst.exe or jpsetup.exe on Windows, indicative of SNAKE installation activity.
sigmahigh2023-05-04Windows process command line matches SNAKE installer argument pattern
Alerts on Windows process command lines containing a 64-hex then 16-hex CLI argument sequence consistent with a malware installer pattern.
sigmahigh2023-05-04Windows Service Creation via SCM (Event ID 7045) with svchost.exe and specific service names
Alerts on Windows 7045 service creations where ImagePath contains svchost.exe and service names match Name/msupdate/msupdate2.
sigmahigh2023-05-02Windows Registry User Profile Creation: ANONYMOUS _DomainUser_ Entries in ProfileList
Alerts on ProfileList registry writes indicating a new user profile with 'ANONYMOUS' and '_DomainUser_' markers.
sigmahigh2023-05-02Windows svchost.exe Loading newdev.dll from AppData Roaming (Potential Persistence)
Alerts on svchost.exe loading newdev.dll from AppData\Roaming, an unusual pattern consistent with stealthy persistence.
sigmahigh2023-05-02Windows Process Execution with User Name "ANONYMOUS" from System32 or AppData
Alerts on Windows process executions where the user is marked "ANONYMOUS" and the parent path is in System32 or AppData.
sigmahigh2023-04-30Windows: Detect newdev.dll created in AppData\Roaming\ starting from C:\Users\
Detects creation of newdev.dll under a user’s AppData\Roaming directory for potential user-scoped persistence.
sigmahigh2023-04-30Windows File Creation of dllhost.exe in Public Documents Used by COLDSTEEL RAT Variants
Flags creation of C:\users\public\Documents\dllhost.exe on Windows, matching an indicator seen in some COLDSTEEL RAT variants.
sigmahigh2023-04-30Rubeus HackTool Execution via PowerShell ScriptBlock Flags (Windows)
Identifies PowerShell ScriptBlock content that includes Rubeus-specific Kerberos and ticket manipulation flags.
sigmaWindowshigh2023-04-27Windows Process Creation Indicators for PowerShell MSI Download and Silent Install (PaperCut MF/NG)
Detects hidden PowerShell downloading a setup.msi and silent msiexec installation tied to PaperCut MF/NG exploitation indicators.
sigmahigh2023-04-25Linux Python Reverse Shell via pty and socket Module Execution
Alerts on Linux executions of Python -c commands that use socket and pty to connect and spawn a potential reverse shell.
sigmaLinuxhigh2023-04-24