Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Creation: Suspicious PowerShell Commandlets Used by Known Exploitation Tools
Alerts on Windows process launches whose command line includes well-known malicious PowerShell commandlet names.
sigmaWindowshigh2023-01-02Linux Process Execution via Vim/Vi/Rvim/Vimdiff Shell and Script Escapes
Detects suspicious Vim/vi/vimdiff/rvim invocations that include Ex commands to run shell/proxy actions.
sigmaLinuxhigh2022-12-28Windows PowerShell Token Obfuscation via Process Command Line
Identifies Windows PowerShell command lines using token obfuscation patterns, common in Invoke-Obfuscation.
sigmaWindowshigh2022-12-27SharpImpersonation Tool Execution on Windows
Flags execution of SharpImpersonation.exe on Windows when command-line parameters indicate token impersonation activity.
sigmaWindowshigh2022-12-27Windows: Execution of Htran/NATBypass HackTool Binaries or Tran/Slave CLI Flags
Detects Windows executions of htran.exe or lcx.exe and command lines containing -tran or -slave flags.
sigmaWindowshigh2022-12-27Potential CVE-2022-46169 Command Injection Probe Against Cacti Web Server
Alert on GET requests to Cacti polldata endpoints containing command-injection payload fragments tied to CVE-2022-46169.
sigmahigh2022-12-27Windows Process Execution: Suspicious AgentExecutor.exe PowerShell Launch with ExecutionPolicy Bypass
Detects AgentExecutor.exe command lines that trigger PowerShell script execution, including remediations and potentially bypassed ExecutionPolicy.
sigmaWindowshigh2022-12-24Windows PowerShell Execution of AADInternals Cmdlets (process creation)
Flags PowerShell processes running AADInternals “-AADInt” cmdlets, indicating potential Azure AD/Office 365 administration or abuse.
sigmaWindowshigh2022-12-23Windows Chromium-Based Browsers Launched with Headless Debugging and User Profile Directory
Alerts on Windows launches of Chromium-based browsers in headless + remote debugging mode targeting a user data directory.
sigmaWindowshigh2022-12-23Windows PowerShell Script Block Logging: AADInternals Cmdlets (Add-AADInt to Update-AADInt) Execution
Flags PowerShell script block execution that contains AADInternals cmdlet names (AADInt), indicating potential admin or abuse activity.
sigmaWindowshigh2022-12-23Windows: Explorer opened from cmd.exe/powershell using shell:MyComputerFolder shortcut
Flags explorer.exe opened for My Computer via shell:mycomputerfolder when started by cmd or PowerShell.
sigmaWindowshigh2022-12-22Detect OWASSRF Webserver Exploitation Pattern Targeting PowerShell Backend
Alerts on successful POST requests to OWA URLs containing PowerShell backend indicators and Exchange-like probe user agents.
sigmahigh2022-12-22Potential OWASSRF Exploitation via OWA Proxy Requests (HTTP 200) - Exchange
Alerts on 200-status proxy POSTs targeting OWA-to-PowerShell backend paths with encoded user info markers.
sigmahigh2022-12-22Linux: New user created with UID=0 or GID=0/10/27 indicating privileged group access
Alerts on Linux user creation events that assign privileged UID/GID values like root, wheel, or sudo.
sigmaLinuxhigh2022-12-21Windows Registry Set Detection of Suspicious Environment Variable Commands
Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.
sigmaWindowshigh2022-12-20Windows Office Binary Execution with Renamed Image Path
Alerts when Office apps are executed under renamed or unexpected image paths, helping catch stealthy masquerading on Windows.
sigmaWindowshigh2022-12-20Windows SQLite CLI Querying Chromium Browser Profile Databases
Alerts when SQLite CLI is used to query Chromium-based browser profile databases containing logins, cookies, or history.
sigmaWindowshigh2022-12-19Windows DLL Sideloading via comctl32.dll in .local directories
Alerts on comctl32.dll loaded from System32 .local folders, consistent with Windows DLL sideloading.
sigmaWindowshigh2022-12-16Windows File Events: Suspicious .exe.local Path With comctl32.dll in System32
Detects System32 *.exe.local entries that reference comctl32.dll, consistent with DLL sideloading behavior.
sigmaWindowshigh2022-12-16Potential CVE-2021-26084 Confluence OGNL RCE Exploitation Attempt via POST
Flags successful POST requests consistent with OGNL injection attempts targeting Confluence page variable endpoints tied to CVE-2021-26084.
sigmahigh2022-12-13