Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
528 rules
Windows PowerShell Web Access Installation via PowerShell Script Block
Detects PowerShell Web Access installation and web authorization configuration from Windows PowerShell script blocks.
sigmaWindowshigh2024-09-03Windows Remote Thread Creation in cmd.exe or PowerShell.exe
Alert on remote thread creation where cmd.exe or PowerShell.exe is the initiating process, excluding common system and Defender sources.
sigmamedium2024-07-29Windows Process Creation: net.exe or PowerShell creating AD group "ESX Admins"
Alerts on net.exe or PowerShell attempts to create a domain group named "ESX Admins" via AD/command-line parameters.
sigmahigh2024-07-29PowerShell Launch With --headless From Conhost.exe on Windows
Flags headless ConHost launching PowerShell on Windows based on process name and command-line arguments.
sigmaWindowsmedium2024-07-23Suspicious PowerShell Execution of DSInternals Cmdlets on Windows
Flags PowerShell command lines invoking specific DSInternals cmdlets that can support AD/credential and key material operations.
sigmaWindowshigh2024-06-26Windows PowerShell ScriptBlock alerts for DSInternals cmdlets
Triggers when PowerShell script blocks include DSInternals cmdlets tied to AD/Azure AD key and password auditing or manipulation.
sigmaWindowshigh2024-06-26Suspicious Child Process of KeyScrambler.exe on Windows
Alerts on KeyScrambler.exe launching cmd.exe, PowerShell, script hosts, regsvr32, or rundll32 as child processes.
sigmaWindowsmedium2024-05-13PowerShell Start-NetEventSession Script Block Execution Indicating Potential Network Capture (Windows)
Alerts when PowerShell ScriptBlocks reference Start-NetEventSession, indicating potential network packet or event capture.
sigmaWindowsmedium2024-05-12Windows PowerShell ScriptBlock Adds Allow Firewall Rule via New-NetFirewallRule
Flags PowerShell ScriptBlock text that invokes New-NetFirewallRule to add an Allow firewall rule.
sigmalow2024-05-10PowerShell New-NetFirewallRule Adds Windows Allow Firewall Rule
Alert on PowerShell creating a new Windows firewall rule that sets the action to Allow via New-NetFirewallRule.
sigmalow2024-05-03Windows Process Creation: Forest Blizzard-related hashes and scheduled task activity
Detects suspicious Windows process execution tied to known hashes or schtasks/PowerShell command-line patterns used for staging and compression.
sigmahigh2024-04-23Winlogon Shell Registry Persistence Attempt (KamiKakaBot Indicators) on Windows
Flags registry changes to Winlogon Shell that include PowerShell-style startup and explorer.exe indicators.
sigmahigh2024-03-22Windows: User Added to Highly Privileged Local/Directory Groups via net.exe or Add-LocalGroupMember
Flags net.exe or PowerShell commands adding users to privileged groups like Group Policy Creator Owners or Schema Admins.
sigmaWindowshigh2024-02-23Suspicious File Downloads via PowerShell.EXE from File Sharing Domains on Windows
Flags PowerShell downloading content from known file-sharing/paste domains using DownloadString/DownloadFile or web request syntax.
sigmaWindowshigh2024-02-23Windows PowerShell ScriptBlock keyword match for WinPwn tool usage
Alerts when PowerShell ScriptBlock text contains WinPwn execution or script/file reference keywords.
sigmaWindowshigh2023-12-04Windows Registry Set in Shell Open Command Using PowerShell Cryptography .NET Classes
Flags registry set of \Shell\Open\Command where PowerShell references System.Security.Cryptography crypto classes.
sigmamedium2023-12-01PowerShell Crypto Namespace Class Invocation for Windows Process Creation
Alerts on PowerShell executions that reference System.Security.Cryptography and common crypto class names.
sigmamedium2023-12-01Windows Elevated Shell Spawn via Process Creation (PowerShell or CMD)
Flags creation of privileged PowerShell or cmd.exe processes tied to an elevated logon context.
sigmamedium2023-11-23Windows Process Creation: Detect Event Log Query via wmic.exe, wevtutil.exe, or PowerShell
Detects command-line attempts to query Windows Event Logs using wevtutil, wmic, or Get-WinEvent/Get-EventLog.
sigmamedium2023-11-20Windows: Detects Suspicious cmd.exe or PowerShell spawned from Confluence (tomcat) Processes
Alerts when Confluence/embedded Tomcat spawns cmd.exe or PowerShell on Windows, indicating possible command execution after exploitation.
sigmamedium2023-11-14