Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Suspicious Windows Process Execution of gatherNetworkInfo.vbs via Cscript/Wscript
Alerts on Windows executions referencing gatherNetworkInfo.vbs in process command lines, indicative of potential discovery activity.
sigmaWindowshigh2023-02-08Windows: Suspicious Outlook VbaProject.OTM Macro File Created
High-confidence file creation alert for Microsoft\Outlook\VbaProject.OTM while excluding outlook.exe.
sigmaWindowshigh2023-02-08Windows OneNote.exe launches cmd/cscript/mshta/PowerShell/wscript with OneNote-exported scripts
Alerts when OneNote.exe spawns common script interpreters to execute OneNote-exported or offline-cache script content.
sigmaWindowshigh2023-02-02macOS OSACompile Run-Only Script Execution
Flags osacompile commands on macOS using run-only (-x) with inline script (-e) execution.
sigmamacOShigh2023-01-31macOS Office Apps Spawning Shell or Scripting Processes
Alerts when Microsoft Office on macOS launches suspicious shell/script or download utilities as child processes.
sigmamacOShigh2023-01-31macOS JXA In-Memory Execution via osascript JavaScript eval and NSData URL loading
Detects osascript-launched in-memory JXA JavaScript execution patterns using eval and URL-based data loading.
sigmamacOShigh2023-01-31Linux process copying passwd or shadow from /tmp
Alerts on Linux cp commands that copy /tmp-based passwd or shadow files.
sigmaLinuxhigh2023-01-31Windows PowerShell Base64-Encoded WMI Class Invocation
Flags PowerShell command lines containing Base64 fragments indicative of WMI class usage (e.g., ShadowCopy, ScheduledJob) on Windows.
sigmaWindowshigh2023-01-30GitHub Audit: High-Risk Security Controls Disabled
Alerts when GitHub audit logs show advanced security, OAuth restrictions, or 2FA requirements disabled for orgs or repos.
sigmahigh2023-01-29GitHub Audit: Dependabot Alerts and Security Updates Disabled
Flags GitHub audit events where Dependabot alerts or security updates are disabled for an organization or repositories.
sigmahigh2023-01-27Linux: Alert on bpf_probe_write_user BPF helper warning strings
Alerts on Linux log messages referencing the bpf_probe_write_user helper warning string, indicating potential suspicious eBPF usage.
sigmaLinuxhigh2023-01-25Windows PowerShell Module Execution Matches Known Offensive PoshModule Script Names
Alerts on Windows PowerShell module executions where the script context matches known offensive PowerShell script/module names.
sigmaWindowshigh2023-01-23Windows: Detect Aruba Netsvc DLL Search Order Hijacking via arubanetsvc.exe Loaded DLLs
Flags arubanetsvc.exe loading targeted DLLs outside standard system paths, suggesting possible DLL search order hijacking.
sigmaWindowshigh2023-01-22Windows rundll32 Launching DLL From Alternate Data Stream (ADS) Paths
Detects rundll32 executions that reference DLLs stored in Alternate Data Streams via ADS-style paths.
sigmaWindowshigh2023-01-21Windows PsExec Remote Execution Creates PSEXEC-*.key File Artefact
Alerts on creation of PsExec key files in C:\Windows\PSEXEC-*.key, indicating remote execution activity.
sigmaWindowshigh2023-01-21Windows Process Creation: svchost DHCPServer RCE Exploitation Attempt
Alerts on svchost.exe running as Network Service with -k DHCPServer, suggesting a potential pre-auth Windows RCE attempt.
sigmahigh2023-01-21Windows PowerShell module commandlet names matching known exploitation and post-exploitation tooling
Alerts on PowerShell module payloads containing commandlet/function names from known malicious exploitation and post-exploitation frameworks.
sigmaWindowshigh2023-01-20Detect CentOS Web Panel POST login reverse-shell RCE attempts (CVE-2022-44877)
Alert on POST requests to CentOS Web Panel login that contain command-execution and reverse-shell style query parameters.
sigmahigh2023-01-20Windows: driverquery.exe Usage for Installed Driver Recon
Alerts when driverquery.exe (drvqry.exe) is launched by script-based parent processes to enumerate installed drivers.
sigmaWindowshigh2023-01-19Windows Successful SMB Logon (Event ID 4624 Logon Type 3) From Public IPs
Flags successful Windows SMB (LogonType 3) logons from non-private, non-local source IP addresses.
sigmaWindowshigh2023-01-19