Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Joomla Webserver: Potential CVE-2023-23752 Exploitation via GET public=true on /api/index.php/v1/
Alerts on GET requests to Joomla API paths with 'public=true' query parameters commonly associated with CVE-2023-23752 probing.
sigmahigh2023-02-23Windows: Mounting Internet Hosted WebDAV Shares via net.exe
Alerts on net.exe (net1.exe) commands that mount an HTTP/WebDAV network share.
sigmaWindowshigh2023-02-21macOS Persistence Attempt Using PlistBuddy to Modify LaunchAgents/LaunchDaemons
Identifies PlistBuddy commands that enable RunAtLoad for LaunchAgents or LaunchDaemons persistence on macOS.
sigmamacOShigh2023-02-18Windows Process Command-Line Containing Unicode Right-to-Left Override (U+202E)
Alerts on Windows process launches with command lines containing Unicode U+202E to support right-to-left text obfuscation.
sigmaWindowshigh2023-02-15Windows: certutil.EXE Downloading Files from File-Sharing Domains via Suspicious Flags
Alert when certutil.exe is run with URL/download flags targeting common file-sharing domains.
sigmaWindowshigh2023-02-15Windows certutil.exe Download from Direct IP Using URL/IP-Related Flags
Alerts when certutil.exe is launched with direct-IP download indicators and download-capable certutil flags.
sigmaWindowshigh2023-02-15Windows certutil.exe Base64/Hex Decode via -decode or -decodehex Flags
Flags certutil.exe use for decoding base64 or hex data via -decode or -decodehex on Windows.
sigmaWindowshigh2023-02-15Windows: CertOC.exe Loading a DLL from User-Writable Paths via -LoadDLL
Alerts on CertOC.exe using -LoadDLL with DLLs from temp/user-writable directories on Windows.
sigmaWindowshigh2023-02-15Windows execution of LocalPotato POC (LocalPotato.exe with specific PE/CLI traits)
Detects LocalPotato.exe process execution on Windows using image path, typical CLI parameters, and known imphash values.
sigmaWindowshigh2023-02-14Potential CVE-2022-21587 Arbitrary File Upload Attempts via Oracle EBS Web Services
Alerts on POST requests with uueupload=TRUE targeting specific Oracle EBS OA_HTML services associated with CVE-2022-21587.
sigmahigh2023-02-13Velocity Application Errors Indicating Potential Server-Side Template Injection
Detects Velocity template rendering exceptions in application error logs that may indicate user-influenced SSTI attempts.
sigmahigh2023-02-11Potential SpEL Injection Attempts Triggering Spring ExpressionException (Application Logs)
Alerts on Spring ExpressionException errors that may indicate potential SpEL injection attempts.
sigmahigh2023-02-11Node.js Application Errors Involving child_process Indicative of RCE Attempts
Flags Node.js ERROR logs mentioning node:child_process, which may signal command execution and possible RCE risk.
sigmahigh2023-02-11JVM Application Logs Indicating Potential XXE via XML Parser Exceptions
Alerts on JVM XML parsing exception messages in application error logs that may indicate attempted XXE exploitation.
sigmahigh2023-02-11JVM Process Execution Exceptions in Application Logs
Flags JVM error logs showing failed process execution (ProcessBuilder/ProcessImpl) that may reflect attempted command execution.
sigmahigh2023-02-11Potential OGNL Expression Injection Exploitation in JVM Application Logs
Detects ERROR-level JVM application log entries containing OGNL parsing/syntax exception indicators that may suggest OGNL injection attempts.
sigmahigh2023-02-11JVM Application Errors Indicating Local File Read Path Traversal Attempts
JVM app error logs with FileNotFoundException plus /../../.. patterns can indicate attempted local file path traversal.
sigmahigh2023-02-11JVM Application Error Logs Indicating Potential JNDI Injection Exploitation
Alerts when JVM application error logs include JNDI/LDAP and Log4j JndiManager keyword indicators.
sigmahigh2023-02-11Windows: Suspicious Executable Created in Temp by OneNote (onenote.exe/onenotem.exe/onenoteim.exe)
Alerts when OneNote creates files in Temp\OneNote with script/executable extensions on Windows.
sigmaWindowshigh2023-02-09Windows Registry: Outlook EnableUnsafeClientMailRules Set to 1
Alerts when Outlook’s EnableUnsafeClientMailRules registry value is enabled (DWORD 0x1), reducing mailbox macro/script protections.
sigmaWindowshigh2023-02-08