Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: SharPersist Execution via Process Image and Scheduled Task/Startup/Registry/Service Command Lines
Detects SharPersist execution on Windows via process name and persistence-related command-line parameters.
sigmaWindowshigh2022-09-15Windows: Service Created by System Using Client with PID 0 (SCM Event 7045)
Alerts on Windows service installation events (SCM EventID 7045) where the client process ID is 0.
sigmaWindowshigh2022-09-15Windows Service Created by Client With PID 0 or Parent PID 0
Alerts on Windows service installs (EID 4697) where the client or parent PID is 0.
sigmaWindowshigh2022-09-15Windows UAC Bypass via Elevated COM interface using ICMLuaUtil
Flags dllhost.exe parent launches tied to elevated COM /Processid GUIDs consistent with UAC bypass behavior on Windows.
sigmaWindowshigh2022-09-13Windows: Taskkill used to terminate ccSvcHst.exe (Symantec Endpoint Protection service impairment)
Flags Windows taskkill /F /IM ccSvcHst.exe executions that can disable Symantec Endpoint Protection services.
sigmaWindowshigh2022-09-13Windows Process Creation: Chisel Tunneling Tool (chisel.exe) Execution
Flags Windows executions of chisel.exe with client/server tunneling and SOCKS5 reverse arguments.
sigmaWindowshigh2022-09-13Windows Process Creation: 3proxy Proxy Server Execution
Detects execution of 3proxy.exe with local 127.0.0.1 proxy binding on Windows.
sigmaWindowshigh2022-09-13PowerShell Disable-WindowsOptionalFeature -Online -FeatureName for Windows Defender features
Detects PowerShell disabling online Windows Defender features via Disable-WindowsOptionalFeature -FeatureName.
sigmaWindowshigh2022-09-10Windows Schtasks.exe Scheduled Task Creation or Modification with Suspicious Schedule Types
Alerts on schtasks.exe commands that schedule tasks using ONLOGON/ONSTART/ONCE/ONIDLE with potentially malicious privilege context.
sigmaWindowshigh2022-09-09Windows schtasks Delete All Scheduled Tasks via /tn * /delete /f
Flags schtasks.exe commands that forcibly delete all scheduled tasks on the local host using /delete /tn * /f.
sigmaWindowshigh2022-09-09Windows schtasks.exe Used to Delete Scheduled Tasks for System and Security Components
Alerts when schtasks.exe runs with /delete targeting sensitive Windows scheduled tasks that support security, updates, or recovery.
sigmaWindowshigh2022-09-09Windows vmnat.exe Renamed Execution for Possible DLL Side-Loading
Alerts on Windows processes where vmnat.exe appears renamed, which may support stealthy execution and DLL side-loading behavior.
sigmaWindowshigh2022-09-09Windows Root Certificate Installation from Suspicious Paths via PowerShell Import-Certificate
Alerts on PowerShell importing a root certificate into Cert:\LocalMachine\Root from suspicious file paths on Windows.
sigmaWindowshigh2022-09-09PowerShell Email Address Exfiltration via EXIF-style Recipient Harvesting on Windows
Alerts when PowerShell command lines enumerate Exchange recipients and expand email address properties, indicating potential email data exfiltration.
sigmaWindowshigh2022-09-09Windows node.exe Execution with -e/--eval and suspicious child process usage
Alerts on node.exe started with -e/--eval and command-line indicators of child_process and net.socket connect activity.
sigmaWindowshigh2022-09-09Windows Process Creation: SharpEvtMute Execution (Event Log Tampering)
Alerts on SharpEvtMute.exe runs with event-log filter and encoded command-line parameters on Windows.
sigmaWindowshigh2022-09-07Windows SysmonEnte Process Access Attempt (Sysmon.exe/ Sysmon64.exe/ Sysmon64a.exe)
Flags attempts to access Sysmon binaries consistent with SysmonEnte execution based on TargetImage, GrantedAccess, and CallTrace.
sigmaWindowshigh2022-09-07Windows: Detect EvtMuteHook.dll Load by IMPHASH Match (SharpEvtMute)
Detects DLL loads with a specific IMPHASH consistent with EvtMuteHook.dll used for event log tampering.
sigmaWindowshigh2022-09-07Windows suspicious file download URLs using direct IP address with script/binary extensions
Alerts on Windows downloads from HTTP/HTTPS direct IP URLs targeting script/binary/shortcut-like filenames.
sigmaWindowshigh2022-09-07Windows Process Creation: WinAPI Function Names in Command-Line
Alerts on Windows processes whose command lines reference WinAPI functions/modules commonly used for dynamic invocation and memory/process manipulation.
sigmaWindowshigh2022-09-06