Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Application: MSMQ Corrupted Packet (Event ID 2027, Level 2)
Alerts on MSMQ Event ID 2027 (level 2) indicating corrupted packets received by the service.
sigmahigh2023-04-21Windows: Suspicious child processes spawned by pc-app.exe (PaperCut MF/NG potential exploitation)
Alert on pc-app.exe spawning common command or scripting utilities on Windows.
sigmahigh2023-04-20Windows Log4j/Wstomcat-related Process Execution via ws_tomcatservice.exe Parent
Detects processes spawned by ws_tomcatservice.exe on Windows, excluding repadmin.exe, to surface potential Tomcat exploitation.
sigmahigh2023-04-20Windows RDP client Mstsc.EXE launched from uncommon browser or email parent process
Alerts when mstsc.exe is spawned by a browser or Outlook, suggesting potential RDP access using a local .rdp file.
sigmaWindowshigh2023-04-18Windows mstsc.exe launched with a local .rdp file from suspicious paths
Alerts on mstsc.exe executions that use a local .rdp file referenced from suspicious command-line paths.
sigmaWindowshigh2023-04-18Windows: Uncommon Process Creates .rdp Remote Desktop File
Alerts on creation of .rdp files by processes that are not typically associated with producing them on Windows.
sigmaWindowshigh2023-04-18Windows winget Install from Zone.Identifier/WinGet Temp Contents Marked by Zone Transfer
Alerts on winget staging under Temp\WinGet combined with ZoneTransfer ZoneId=3 and Zone.Identifier ADS contents.
sigmaWindowshigh2023-04-18Windows Winget adds HTTP package source
Alerts when winget is used to add a package source pointing to an http:// URL.
sigmaWindowshigh2023-04-17Windows Process Creation: Crassus Privilege Escalation Discovery Tool Execution
Identifies execution of the Crassus Windows privilege escalation discovery tool via process metadata.
sigmaWindowshigh2023-04-17Windows: Stracciatella.exe Process Execution Identification (SharpPick behavior)
Alerts on Windows process creation for Stracciatella.exe using PE metadata and known SHA256 hashes.
sigmaWindowshigh2023-04-17Windows Process Creation: Certipy Tool Execution Based on PE and CLI Parameters
Flags Certipy.exe execution on Windows using PE metadata and Certipy-like AD CS command-line arguments.
sigmaWindowshigh2023-04-17Windows HackTool Certify Execution via Certify.exe and common AD abuse arguments
Identifies Windows processes running Certify.exe with AD certificate abuse-oriented command line arguments.
sigmaWindowshigh2023-04-17Windows: Unexpected Termination of Message Queuing (MSMQ) Service via SCM Event 7034
Flags Service Control Manager Event ID 7034 for unexpected termination of the Message Queuing (MSMQ) service.
sigmaWindowshigh2023-04-14Windows Service Control Manager: Termination of Security-Critical Services With Error
Alerts on error-terminated Windows security and infrastructure services from Service Control Manager event 7023.
sigmaWindowshigh2023-04-14Windows: Suspicious subprocesses launched by mqsvc.exe consistent with CVE-2023-21554 exploitation
Alerts when mqsvc.exe spawns common scripting/utility executables often used for unauthorized execution.
sigmahigh2023-04-12Linux Process Creation: PHP CLI Inline Code Using fsockopen with -r
Alerts on Linux executions of php -r inline code that references fsockopen, consistent with outbound reverse-shell style socket creation.
sigmaLinuxhigh2023-04-07Linux Perl Reverse Shell Execution via Perl -e and Socket/exec Patterns
Detects perl -e one-liners on Linux that include Perl Socket::INET reverse-shell code patterns and exec/connect logic.
sigmaLinuxhigh2023-04-07Linux netcat/ncat Execution with -e and Shell Invocation
Alerts on Linux executions of nc/ncat using -e that reference common shells, indicating potential reverse-shell setup.
sigmaLinuxhigh2023-04-07Okta Failed Login with Password-Like AlternateID Value
Alerts on Okta login_failed events with alternateId values that may contain password data, risking credential exposure in logs.
sigmaIdentityhigh2023-04-03Possible ICO C2 File Downloads via Proxy: Compromised 3CXDesktopApp
Flags proxy requests for 3CXDesktopApp icon storage URIs ending in .ico, indicating potential malicious payload downloads.
sigmahigh2023-03-31