Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Suspicious child processes spawned by ManageEngine ServiceDesk Plus (java.exe parent)
Alerts when ManageEngine ServiceDesk Java spawns common attacker tools like PowerShell, certutil, mshta, or wmic.
sigmaWindowshigh2023-01-18Windows Firewall Rules Deleted (Windows Defender Firewall) via Firewall-as Events
Alerts on Windows Defender Firewall configurations where all rules are deleted (Event 2033/2059), signaling potential defense impairment.
sigmaWindowshigh2023-01-17Windows DNS Client: DNS query for anonfiles.com domain
Alerts when Windows DNS client logs show a DNS query containing .anonfiles.com.
sigmaWindowshigh2023-01-16Windows Registry: Excel Options Run Entry Point for XLL Add-in Persistence
Flags registry writes that reference an Excel XLL add-in via a '/R ' command under Excel Options.
sigmaWindowshigh2023-01-15Windows Registry: DisableRestrictedAdmin Value Tampering to Change Restricted Admin Mode
Flags registry modifications to DisableRestrictedAdmin that change Restricted Admin mode settings.
sigmaWindowshigh2023-01-13Windows Process Creation: Registry Tampering of DisableRestrictedAdmin in Lsa Key
Alerts when a process command line references LSA DisableRestrictedAdmin to change RestrictedAdmin behavior via the registry.
sigmaWindowshigh2023-01-13Windows Task Scheduler: Detects Scheduled Task Deletion or Disabling (Task Deleted/Disabled)
Alert on deletion or disabling of targeted Windows scheduled tasks tied to system, security, and update components.
sigmaWindowshigh2023-01-13Windows Registry change enabling developer features for sideloading and untrusted app installs
Alerts on registry writes that enable Windows developer feature policies allowing sideloading of untrusted apps.
sigmaWindowshigh2023-01-12Windows SRP restricted application access (Event IDs 865, 866, 867, 868, 882)
Flags Windows SRP enforcement events where attempts to access applications are restricted by administrator policy.
sigmaWindowshigh2023-01-12Windows process activity enabling Developer Mode or sideloading via SystemSettingsAdminFlows.exe
Alerts on SystemSettingsAdminFlows.exe command lines enabling Developer Mode unlock or application sideloading.
sigmaWindowshigh2023-01-11Windows Process Creation: PowerShell Execution Policy Registry Tampering via CommandLine
Alerts when a process command line references PowerShell ExecutionPolicy registry paths and weaker policy values.
sigmaWindowshigh2023-01-11Windows BITS Client Job Downloads from Direct IP Addresses
Alerts when Windows BITS Client downloads via HTTP/HTTPS URLs containing direct IP addresses.
sigmaWindowshigh2023-01-11Windows AppX Deployment: Staged Directory Package Added to Pipeline
Alerts when AppX deployment processing references a package located in typical staging directories such as Temp or Downloads.
sigmaWindowshigh2023-01-11Windows AppX Deployment Server downloads AppX from File Sharing or CDN Domains
Alerts when an AppX package is pulled for processing from file sharing/CDN domains via the Windows AppX deployment server.
sigmaWindowshigh2023-01-11Azure Sign-In: Successful single-factor atRisk logins from non-registered devices
Alerts on at-risk successful Azure sign-ins from devices with missing trust type when MFA isn’t required.
sigmaCloudhigh2023-01-10Windows Suspicious Double-Extension Execution via Parent Command Line
Alerts on Windows processes launched by parents whose image/command line includes disguised double-extension tokens.
sigmaWindowshigh2023-01-06Windows PowerShell: ScriptBlock using security descriptor (Win32_Trustee/Win32_Ace) and LSA data strings
Alerts on PowerShell ScriptBlock text that manipulates security descriptors and LSA-related identifiers, indicating possible persistence behavior.
sigmaWindowshigh2023-01-05Windows Registry AMSI COM Server Hijacking via InProcServer32 CLSID Modification
Alerts on registry changes that alter an AMSI COM CLSID InProcServer32 entry to break AMSI loading.
sigmaWindowshigh2023-01-04Linux process execution matches known hacktools by image name
Alerts on Linux process executions of known hacktool, scanner, web enumeration, and exploit utility binaries by image name.
sigmaLinuxhigh2023-01-03Windows Registry EventLog Service File Location Tampering
Flags registry modifications that change the EventLog service’s configured log file location on Windows.
sigmaWindowshigh2023-01-02