Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows PowerTool Process Execution
Flags Windows process creation events where PowerTool.exe/PowerTool64.exe is launched.
sigmaWindowshigh2022-11-29Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
Flags successful Azure sign-ins where the User-Agent contains "azurehound", indicating AzureHound discovery.
sigmaCloudhigh2022-11-27Windows UAC Bypass via Event Viewer RecentViews Path in Process Command Line
Flags Windows processes whose command lines reference Event Viewer RecentViews and use redirection, consistent with UAC bypass techniques.
sigmaWindowshigh2022-11-22Windows Registry NGenAssemblyUsageLog Key Tampering via .NET Usage Log Configuration
Alerts on registry modifications to the .NETFramework NGenAssemblyUsageLog key that can disrupt .NET Usage Log creation.
sigmaWindowshigh2022-11-18Windows file activity matching CrackMapExec/Impacket-secretsdump credential dumping temp output patterns
Alerts on Windows temp file creations consistent with CrackMapExec or Impacket-secretsdump credential dumping activity.
sigmaWindowshigh2022-11-16Windows Driver Load: Process Hacker (processhacker.sys) Presence
Flags Windows driver loads of Process Hacker’s processhacker.sys using path and known imphash indicators.
sigmaWindowshigh2022-11-16Windows Code Integrity blocked image/driver loads due to signature level or policy violations
Alerts on Windows Code Integrity Event ID 3077 when an image/driver load is blocked for signing-level or policy violations.
sigmaWindowshigh2022-11-10Windows Process Creation: Sysmon.exe as Parent of Spawned Process
Alerts when Sysmon.exe/Sysmon64.exe is the parent of a new process, a potentially suspicious execution chain on Windows.
sigmahigh2022-11-10PowerShell AMSI Bypass Assembly GetType Pattern in Script Block Text
Flags PowerShell scripts containing a reflection-based AMSI bypass fragment with GetType and SetValue($null,$true).
sigmaWindowshigh2022-11-09Windows System: Kerberos KDC RC4-HMAC downgrade exploit attempts (CVE-2022-37966)
Identifies Windows Kerberos KDC error events tied to RC4-HMAC downgrade/auth negotiation exploitation behavior (CVE-2022-37966).
sigmahigh2022-11-09Windows AppCmd Password Listing Activity via IIS Service Credentials Exposure
Flags appcmd.exe executions that include password-related listing parameters for IIS service account credentials.
sigmaWindowshigh2022-11-08Windows process creation: suspicious ping wait followed by del file deletion
Flags cmd/powershell command lines that use ping -n with Nul redirection followed by Del /f /q to delete a file.
sigmaWindowshigh2022-11-03Windows Executable Initiating Connections to ngrok Tunnel Domains
Flags Windows network connections to ngrok tunnel subdomains that may indicate tunneling for C2 or staging.
sigmaWindowshigh2022-11-03Linux network connections to ngrok tunneling endpoints
Alerts on Linux connections to ngrok tunnel domains, which may indicate tunneling-based C2 or exfiltration.
sigmaLinuxhigh2022-11-03Windows: Detect kavremover-related LOLBIN command-line usage
Alerts on Windows process executions with 'run run-cmd' using kavremover/cleanapi-style LOLBIN invocation patterns.
sigmaWindowshigh2022-11-01Windows Image Load: Uncommon VSSAPI DLL (vssapi.dll) by Suspicious Executables
Alerts when uncommon processes load vssapi.dll, a Shadow Copy–related DLL, using image load telemetry with path-based exclusions.
sigmaWindowshigh2022-10-31Windows Process Command Lines Referencing Dot-Suffixed File Names
Alerts on Windows process executions whose command lines reference file-path strings ending with a dot.
sigmahigh2022-10-28Windows Exchange PowerShell Cmdlet History Log Files Deleted
Flags deletion of Exchange PowerShell cmdlet history log files in the expected logging directory.
sigmaWindowshigh2022-10-26Windows: Registry change disabling MacroRuntimeScanScope runtime macro scanning
Flags Office registry updates that set MacroRuntimeScanScope to 0x00000000, disabling runtime scanning for enabled macros.
sigmaWindowshigh2022-10-25PowerShell: Suspicious Set-Service DACL/SecurityDescriptor Modification for Hidden Services
Flags PowerShell ScriptBlock activity using Set-Service with specific SDDL elements consistent with hiding services from tools like sc.exe.
sigmaWindowshigh2022-10-24