Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
117 rules
Windows: Detect winPEAS privilege escalation reconnaissance execution
Flags Windows executions of winPEAS/PEASS-ng based on image name and command-line discovery options and release download indicators.
sigmaWindowshigh2022-09-19Windows PowerShell Sensitive File Discovery via ScriptBlock Enumeration
PowerShell script blocks using recursive file enumeration that target sensitive file extensions.
sigmaWindowsmedium2022-09-16PowerShell User Discovery and Export with Get-ADUser
Flags PowerShell Get-ADUser enumeration (filter *) followed by exporting results to a file.
sigmaWindowsmedium2022-09-09Windows WMIC System Reconnaissance Using "computersystem" Flag
Flags wmic.exe runs that include the "computersystem" argument for Windows host information discovery.
sigmaWindowsmedium2022-09-08Windows Process Creation: Renamed AdFind.exe Executions
Detects renamed AdFind.exe executions using AdFind-style domain discovery command-line indicators, OriginalFileName, and known binary hashes.
sigmaWindowshigh2022-08-21Windows: DirLister.exe Execution for Directory Listing Discovery
Alerts on execution of DirLister.exe on Windows, indicating potential directory/file discovery activity.
sigmaWindowslow2022-08-20Windows DNS Query for _ldap.* Using LDAP-Related Discovery
Alerts on _ldap.* DNS queries from uncommon Windows processes, indicating potential LDAP/DNS service discovery.
sigmaWindowslow2022-08-20Windows Command-Line Tools Performing Web POST Exfiltration via IWR/curl/wget
Identifies PowerShell/curl/wget commands on Windows that use POST-style web requests combined with data-dumping or discovery payloads.
sigmaWindowshigh2022-08-02Linux Process Recon: Find SUID/htpasswd Files via Command-Line Patterns
Flags Linux command-line reconnaissance patterns for .htpasswd discovery and setuid (-perm -4000) file enumeration.
sigmaLinuxhigh2022-06-20Windows Process Creation: Sysinternals PsService (PsService*.exe) Execution
Alerts on execution of Sysinternals PsService (PsService*.exe) on Windows, which can support service discovery and tampering.
sigmaWindowsmedium2022-06-16Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.
sigmaWindowslow2022-06-04Windows Process Creation: gpresult.exe Group Policy (RSoP) Discovery (/z /v)
Flags process executions of gpresult.exe that request RSoP details using /z and /v on Windows.
sigmaWindowsmedium2022-05-01Windows PowerShell User Discovery via Current Username APIs
Alerts on PowerShell script blocks that retrieve the current username or user identity using common environment/.NET calls.
sigmaWindowslow2022-04-04Windows PowerShell: Suspicious Process Discovery Using Get-Process
Alerts when PowerShell script blocks contain Get-Process, indicating local process discovery activity.
sigmaWindowslow2022-03-17PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
sigmaWindowslow2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
sigmaWindowslow2022-03-17Windows CHCP Console Code Page Lookup Triggered From cmd.exe
Flags cmd.exe-launched chcp.com executions likely used to query system code page/locale for discovery.
sigmaWindowsmedium2022-02-21Microsoft 365 eDiscovery PST Export or Search Started Success Alert
Alerts on successful eDiscovery search/export activity that produces PST files in Microsoft 365.
sigmaCloudmedium2022-02-08Windows Process Command Line Network Recon via nslookup LDAP SRV Query
Identifies Windows command lines running nslookup with an LDAP SRV domain controller discovery query string.
sigmaWindowshigh2022-02-07Windows Process Creation: Suspicious systeminfo.exe Execution
Alerts on execution of systeminfo.exe (or sysinfo.exe) via Windows process creation logs for system discovery.
sigmaWindowslow2022-01-01