Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Alerts on registry changes to Windows legal notice caption/text containing ransomware-style keywords.
sigmaWindowshigh2022-12-11Windows: Alert on Unusual Child Process of Setres.EXE Spawning 'choice' Executables
Identifies uncommon setres.exe children matching '\choice' while excluding System32/SysWOW64 choice.exe.
sigmaWindowshigh2022-12-11Windows Privilege Escalation via mklink Symlink Between cmd.exe and osk.exe
Alerts on mklink creating a symlink between osk.exe and cmd.exe, enabling potential login-screen privilege escalation.
sigmaWindowshigh2022-12-11Windows Image Load of Specific System DLLs Not Normally Present in System Directories
Alerts on image load events for specific system-path DLLs with unexpected “phantom” DLL names on Windows.
sigmaWindowshigh2022-12-09Windows Registry: LSASS Full Dump via WER LocalDumps DumpType=2
Flags registry changes enabling LSASS full memory dumps by setting WER LocalDumps DumpType to 0x2.
sigmaWindowshigh2022-12-08Windows: LSASS Dump (.dmp) Files in CrashDumps Folder
Alerts when an lsass.exe dump (.dmp) appears in the Windows CrashDumps directory under systemprofile.
sigmaWindowshigh2022-12-08Windows Application Error: LSASS (lsass.exe) Crashed (Event ID 1000)
Alerts on Application Error (Event ID 1000) entries where lsass.exe crashes, using Windows Application event telemetry.
sigmaWindowshigh2022-12-07Windows windefend alerts on suspicious Windows Defender configuration changes (Disable* and SpyNet reporting)
Alerts on windefend Event 5007 when Defender configuration changes set features like anti-spyware, scanning, or SpyNet reporting to disabled values.
sigmaWindowshigh2022-12-06Windows Windefend: Defender Restored File from Quarantine (EventID 1009)
Alerts on Windows Defender Windefend events indicating an item was restored from quarantine (Event ID 1009).
sigmaWindowshigh2022-12-06Windows Process Creation: Command Line Contains Emoji Characters
Alerts on Windows process executions whose command line includes emoji/symbol characters from a predefined list.
sigmaWindowshigh2022-12-05Windows Process Command Line Contains Emoji Characters
Alerts when a Windows process command line includes emoji characters, which can be used to obscure activity or bypass naive detections.
sigmaWindowshigh2022-12-05Windows Process Creation: Command Line Contains Specific Emoji Characters
Alerts when a Windows process command line includes specific emoji Unicode characters that may be used for evasion or obfuscation.
sigmaWindowshigh2022-12-05Windows Process Creation Command-Line Contains Emoji Characters
Alerts on Windows executions whose command line includes emoji Unicode characters.
sigmaWindowshigh2022-12-05Windows Process Creation: Renamed Mavinject32/64.EXE Execution
Alerts on renamed executions of mavinject32.exe/mavinject64.exe based on OriginalFileName and image path.
sigmaWindowshigh2022-12-05Windows Security: Suspicious Scheduled Task Update via Event ID 4702 Keywords
Alerts when a scheduled task is updated (EventID 4702) and the new task content includes suspicious execution keywords or temp/user paths.
sigmaWindowshigh2022-12-05Windows Security Audit: Scheduled Task Deleted or Disabled (Important Task Names)
Alerts on deletion or disabling of important Windows scheduled tasks based on Security audit events 4699 and 4701.
sigmaWindowshigh2022-12-05Windows Security: Suspicious Scheduled Task Creation via Event 4698
Alerts on Windows scheduled task creation (EventID 4698) when TaskContent contains suspicious directories or command patterns.
sigmaWindowshigh2022-12-05Windows Process Execution of wsudo with System or TrustedInstaller
Alerts on wsudo.exe runs from wsudo-bridge.exe requesting execution as System or TrustedInstaller.
sigmaWindowshigh2022-12-02Windows DLL Sideloading via Loading ShellChromeAPI.dll
Alerts when Windows processes attempt to load ShellChromeAPI.dll, a DLL typically not present on systems.
sigmaWindowshigh2022-12-01Windows: Gpg4win (GnuPG) Encrypt/Decrypt Command Using Suspicious File Paths
Flags Gpg4win/GnuPG file crypto commands using -passphrase with activity in temporary/public or suspicious Windows directories.
sigmaWindowshigh2022-11-30