Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
528 rules
PowerShell ScriptBlock WebClient Download Calls
Alert on PowerShell ScriptBlock text that uses System.Net.WebClient to download files or strings from the Internet.
sigmaWindowsmedium2017-03-05Windows PowerShell Script Block Logging: PSAttack marker string
Alerts when PowerShell script blocks contain the "PS ATTACK!!!" marker on Windows.
sigmaWindowshigh2017-03-05Windows PowerShell Script Block Contains Exploitation Framework and Credential Theft Keywords
Alerts on PowerShell script block text containing known exploitation, token, and memory-related keywords.
sigmaWindowsmedium2017-03-05Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Alerts when PowerShell ScriptBlock text includes strings matching known malicious commandlets from common exploitation toolsets.
sigmaWindowshigh2017-03-05Suspicious PowerShell Module Usage with Hidden/Encoded Execution Parameters on Windows
Flags hidden or encoded PowerShell invocations that decode/execute code or download-and-execute patterns, while filtering a Chocolatey installer snippet.
sigmaWindowshigh2017-03-05Suspicious PowerShell WebClient Downloads via PoshModule
Alerts on PowerShell module activity referencing System.Net.WebClient with DownloadFile/DownloadString calls to fetch remote content.
sigmaWindowsmedium2017-03-05Windows PowerShell Execution via EngineVersion/HostVersion Mismatch in Command Start Telemetry
Detects PowerShell execution attempts that match a specific executable EngineVersion/HostVersion mismatch pattern on Windows.
sigmaWindowshigh2017-03-05PowerShell Net.WebClient DownloadFile/DownloadString Usage (Classic)
Flags PowerShell Classic commands using Net.WebClient to download content via DownloadFile or DownloadString.
sigmaWindowslow2017-03-05