Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
Windows: Detect Named Pipe Creation with Koh Default Names
Alerts on Windows named pipe creation with Koh default identifiers in the pipe name.
sigmaWindowscritical2022-07-08Windows File Events: wmiexec Default Output File Creation (__1<9 digits>.<1-7 digits>)
Detects Windows file creation matching wmiexec default output filename patterns in admin share and drive paths.
sigmaWindowscritical2022-06-02Antivirus ransomware signature match (Babuk, Lockbit, Ryuk, WannaCry)
Flags antivirus ransomware detections when the alert signature contains known ransomware family name strings.
sigmacritical2022-05-12Windows Hacktool Execution Flagged by Imphash in Process Creation
Alerts on Windows process executions where the import hash matches known hacktool binaries, even if renamed.
sigmaWindowscritical2022-03-04Windows Process Creation: DumpStack.log Used to Evade Microsoft Defender
Alerts on Windows processes launched with DumpStack.log in the image name and command-line output argument.
sigmaWindowscritical2022-01-06Grafana Web Path Traversal Exploitation (CVE-2021-43798) With 200 Responses
Alerts on Grafana web requests with traversal patterns in the URI query that return HTTP 200.
sigmacritical2021-12-08Windows PowerShell Process Creation with DInjector Cradle Flags (/am51 and /password)
Identifies Dinject PowerShell cradle usage by matching command-line flags '/am51' and '/password' in Windows process creation.
sigmaWindowscritical2021-12-07Windows LSASS Process Clone Execution Observed
Alerts on process creation where LSASS creates a new LSASS clone, which may indicate credential dumping activity.
sigmaWindowscritical2021-11-27Windows Process Creation: cmd.exe Spawned from Edge Elevation Service (CVE-2021-41379)
Alerts when cmd.exe or PowerShell spawns under Edge elevation service with SYSTEM integrity, consistent with CVE-2021-41379 exploitation.
sigmacritical2021-11-22Windows MSI Exec Creates elevation_service.exe Under Edge Path (CVE-2021-41379)
Flags msiexec creating elevation_service.exe within the Microsoft Edge application directory, indicating potential LPE exploitation.
sigmacritical2021-11-22Suspicious DNS Query Patterns for Cobalt Strike Beacons on Windows (Sysmon)
Alerts on Windows Sysmon DNS queries with QueryName patterns consistent with Cobalt Strike DNS beaconing.
sigmaWindowscritical2021-11-09Windows HackTool Activity: Mimikatz Kerberos Ticket and MemSSP File Creation
Alerts on Windows file creation events for Mimikatz-related .kirbi and mimilsa.log files.
sigmaWindowscritical2021-11-08Linux Network Connection to /bin/bash via Reverse Shell Pattern
Alerts on /bin/bash network connections to non-local destination IPs, consistent with reverse shell behavior.
sigmaLinuxcritical2021-10-16Linux auditd: Detect processes using --cpu-priority command-line parameter (possible miner behavior)
Alerts on Linux processes whose command line includes --cpu-priority, a common miner CPU tuning flag.
sigmaLinuxcritical2021-10-09Windows DLL Hijacking via Forced Load of C:\Windows\ADFS\version.dll
Alert on loading C:\Windows\ADFS\version.dll, a DLL hijacking indicator consistent with the FoggyWeb technique.
sigmacritical2021-09-27Zoho ManageEngine ADSelfService Plus CVE-2021-40539 REST API exploit URL access (Web)
Flags web requests targeting ADSelfService Plus REST API paths linked to CVE-2021-40539 authentication bypass.
sigmacritical2021-09-10Microsoft Exchange ProxyToken Exploitation via ECP POST and InboxRules NewObject (CVE-2021-33766)
Flags POSTs to Exchange ECP InboxRules endpoints with SecurityToken= that return HTTP 500, indicating ProxyToken exploitation attempts.
sigmacritical2021-08-30Windows Process Creation Matching TrustedPath UAC Bypass Directory Mocking Strings
Alerts on Windows processes referencing System32/SysWOW64 paths consistent with TrustedPath UAC bypass directory mocking.
sigmaWindowscritical2021-08-27MODX Manager Path Traversal Attempt via tvs.php class_key (CVE-2010-5278)
Alerts on HTTP requests to MODx tvs.php with traversal-based class_key payload indicative of LFI attempts.
sigmacritical2021-08-25Web Exploitation of Arcadyan Router Path Traversal and Config Injection Attempts
Detects Arcadyan router exploit traffic by matching URL-encoded path traversal patterns in query strings linked to config injection.
sigmacritical2021-08-24