Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Proxy Beaconing to 3CX-Related Domains Indicating Possible Compromise
Flags proxy requests to 3CX-related domains that may indicate C2 beaconing behavior.
sigmahigh2023-03-29Windows: Flag 3CXDesktopApp updater fetching a known compromised update URL
Alerts on 3CXDesktopApp updater.exe launched with update arguments pointing to a known compromised HTTP update path.
sigmahigh2023-03-29Windows Process Creation: Suspicious Child Executables Spawned by 3CXDesktopApp.exe
Alerts on suspicious execution utilities spawned by 3CXDesktopApp.exe via Windows process creation events.
sigmahigh2023-03-29Windows Process Creation: 3CXDesktopApp Execution from Known Compromised Hashes
Alerts when 3CXDesktopApp.exe executes on Windows with hash/version indicators matching known compromised binaries.
sigmahigh2023-03-29Windows 3CXDesktopApp.exe Beaconing to Suspicious 3CX-Related Domains (Netcon)
Potential Compromised 3CXDesktopApp Beaconing Activity - Netcon
sigmahigh2023-03-29Windows DNS: Detect potential beaconing to domains associated with 3CXDesktopApp compromise
Potential Compromised 3CXDesktopApp Beaconing Activity - DNS
sigmahigh2023-03-29Windows Process Creation: Sysinternals PsSuspend Targeting msmpeng.exe
Alerts on execution of Sysinternals PsSuspend with command line referencing msmpeng.exe.
sigmaWindowshigh2023-03-23Windows DLL sideloading: iviewers.dll loaded from non-Windows Kits paths
Alerts on unexpected loads of iviewers.dll outside Windows Kits paths, consistent with DLL sideloading attempts.
sigmaWindowshigh2023-03-21Azure Sign-in Success with Legacy Client User-Agent Indicators (MFA Bypass Suspicion)
Alerts on successful Azure sign-ins using legacy client user-agent markers that may indicate MFA bypass attempts.
sigmaCloudhigh2023-03-20Windows svchost.exe Spawning rundll32.exe with WebDav davclnt.dll DavSetCookie
Alerts on svchost.exe launching rundll32.exe to run davclnt.dll DavSetCookie for WebDav over a non-local IP.
sigmaWindowshigh2023-03-16Windows Registry: Hypervisor Enforced Code Integrity Enabled DWORD Set to 0
Alerts when HVCI-related registry values are set to 0, indicating Hypervisor Enforced Code Integrity has been disabled.
sigmaWindowshigh2023-03-14Windows Process Creation: Sysinternals ADExplorer Snapshot Exports Active Directory Database
Flags Sysinternals ADExplorer running with -snapshot to export an Active Directory database to suspicious local directories.
sigmaWindowshigh2023-03-14Windows Registry Event for Potential Qakbot/IceID Persistence Key
Alerts on Windows registry events referencing a specific \\Software\\firm\\soft\\Name key suffix linked to Qakbot/IceID-like activity.
sigmaWindowshigh2023-03-13Windows Rundll32 Execution Masquerading as Image Files via Image Extensions
Flags rundll32.exe executions whose command line references image file extensions used for DLL masquerading.
sigmaWindowshigh2023-03-13Windows Rcdll.dll DLL Sideloading via Image Load Path
Flags rcdll.dll loads from unexpected locations, excluding Visual Studio and Windows Kits directories.
sigmaWindowshigh2023-03-13Windows Process Creation: mshta/VBScript Launching PowerShell and Embedded Backdoor Logic
Alerts on Windows command lines combining mshta VBScript execution bypass, system survey WMI queries, and PowerShell HTTP/Base64 patterns.
sigmahigh2023-03-10Windows PowerShell Execution with Encoded Hidden Execution Flags (Wmiexec)
Flags PowerShell process launches containing the Wmiexec default hidden/no-profile/execution-bypass flag sequence.
sigmaWindowshigh2023-03-08Windows sc.exe Service Security Descriptor Changes via sdset
Alerts on sc.exe sdset activity that modifies a service security descriptor to grant access to targeted principals.
sigmaWindowshigh2023-02-28Windows Firewall Exception Rule Added for Application in Suspicious Path
Flags new Windows Defender Firewall exception rules for apps located in Temp/PerfLogs/Public/Tasks-like directories.
sigmaWindowshigh2023-02-26Windows wscript.exe DNS Queries to Potentially Malicious Hex-Label Domains
Alerts when wscript.exe triggers DNS lookups for domains matching a C2-like regex pattern.
sigmahigh2023-02-23