Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Registry: User Shell Folders Value Modification via reg.exe or PowerShell
Alerts when reg.exe or PowerShell modifies User Shell Folders/Shell Folders Startup-related registry values.
sigmaWindowshigh2026-01-05Windows: Kernel Driver Utility (KDU) and hamakaze.exe Execution
Alerts on KDU/hamakaze.exe launches with command-line parameters associated with kernel driver loading.
sigmaWindowshigh2026-01-02Windows devcon.exe Command Line Disabling VMware VMCI Device
Flags devcon.exe command lines that disable VMware VMCI using VMCI PCI ID or VMWVMCIHOSTDEV driver markers.
sigmaWindowshigh2026-01-02Windows Registry Set: Disable Windows Credential Guard by Zeroing EnableVirtualizationBasedSecurity
Alerts on registry value changes that zero Credential Guard/LSA configuration flags to disable virtualization-based secret protection.
sigmaWindowshigh2025-12-26Windows Registry Delete of Credential Guard EnableVirtualizationBasedSecurity or LsaCfgFlags
Flags deletion of Credential Guard/LSA-related registry values that may weaken virtualization-based secret protection.
sigmaWindowshigh2025-12-26Windows Credential Guard Registry Key Tampering via reg.exe or PowerShell Command Line
Alerts on PowerShell/Reg.exe commands that add/modify/delete DeviceGuard/LSA registry values tied to Credential Guard.
sigmaWindowshigh2025-12-26Windows AMSI Disabled by Registry Value Modification (AmsiEnable)
Alerts when Windows Script Settings AmsiEnable is set to 0x00000000 to disable AMSI.
sigmaWindowshigh2025-12-25Windows Process Creation: Registry Modification to Disable ETW AutoLogger via reg.exe or PowerShell
Flags reg.exe or PowerShell registry changes aimed at disabling WMI AutoLogger EventLog session components.
sigmaWindowshigh2025-12-25Windows Process Command-Line Tampering of AMSI Registry Values via reg.exe or PowerShell
Alerts on reg.exe or PowerShell command lines attempting to add/set AMSI enable registry settings.
sigmaWindowshigh2025-12-25Windows File Events: Legitimate Applications Writing Executables to Uncommon Locations
Alerts when selected Windows binaries write files to typically uncommon directories such as Temp, ProgramData, AppData, or system areas.
sigmaWindowshigh2025-12-10Linux process creation: suspicious child processes launched by Node.js server command execution
Flags Linux processes where a Node.js server child-process pattern launches suspicious shell/command tooling.
sigmahigh2025-12-05Windows Process Creation: npm install for Shai-Hulud 2.0 Malicious Package Names and Versions
Alert on Windows node.exe running npm install with command-line package/version strings known from the Shai-Hulud 2.0 npm campaign.
sigmahigh2025-11-28Linux Process Creation: npm install of Shai-Hulud 2.0 malicious packages by name and version
Alerts on Linux npm install commands referencing known Shai-Hulud 2.0 malicious package versions.
sigmahigh2025-11-28Windows Schtasks Execution with Renamed schtasks.exe Binary
Alerts on scheduled task management commands that use a renamed schtasks.exe binary on Windows.
sigmaWindowshigh2025-11-27Windows Process Access: WerFaultSecure accessing MsMpEng with dbgcore.dll/dbghelp.dll call traces
Alerts on WerFaultSecure.exe accessing MsMpEng.exe with dbgcore/dbghelp DLLs in the call trace.
sigmaWindowshigh2025-11-27Windows suspicious access to LSASS.exe with dbgcore.dll/dbghelp.dll call trace from uncommon paths
Alerts on suspicious LSASS access from unusual locations when dbgcore.dll or dbghelp.dll appears in the call trace.
sigmaWindowshigh2025-11-27Windows Image Load: dbgcore.dll/dbghelp.dll Loaded from Uncommon User and System Paths
Alerts when dbgcore.dll or dbghelp.dll is loaded from user or other uncommon directories on Windows.
sigmaWindowshigh2025-11-27AWS CloudTrail GuardDuty Detector Deleted or Disabled via UpdateDetector
Identifies successful GuardDuty detector deletion or disablement from CloudTrail, reducing GuardDuty monitoring coverage.
sigmaCloudhigh2025-11-27Windows Process Creation: Grixba Reconnaissance Tool Command-Line Parameter Combination
Alerts on Windows command lines containing Grixba-like mode/input/scan parameter combinations during reconnaissance.
sigmahigh2025-11-26Windows Script Interpreter Launching trufflehog or gitleaks Credential Scanner
Flags node.exe or bun.exe spawning trufflehog/gitleaks to perform secret or credential scanning.
sigmaWindowshigh2025-11-25