Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Creation: Renamed Sysinternals Sdelete Execution
Alerts on Windows processes created with OriginalFileName sdelete.exe but executed via renamed sdelete binary paths.
sigmaWindowshigh2022-09-06Windows SharpChisel Command-Line Execution via SharpChisel.exe
Alerts on Windows process executions where the SharpChisel executable or Product metadata indicates SharpChisel.
sigmaWindowshigh2022-09-05Windows: Detect QuarksPwDump.exe Credential Dumping via Command-Line Parameters
Flags QuarksPwDump.exe executions on Windows that attempt local/domain hash and related data dumping.
sigmaWindowshigh2022-09-05Windows File Events: Suspicious Executable File Name Creation
Alerts on Windows file creation with suspicious executable filename patterns, including .bat.exe/.sys.exe and deceptive path-based names.
sigmaWindowshigh2022-09-05Windows Registry Tampering Targeting Sophos AV Tamper Protection Enabled Flags
Flags Windows registry changes that disable Sophos AV tamper protection by clearing specific enabled DWORD values.
sigmaWindowshigh2022-09-02Windows Process Creation: reg.exe Adds or Copies SafeBoot Registry Keys
Flags reg.exe with add/copy used against SafeBoot registry keys in Windows process creation logs.
sigmaWindowshigh2022-09-02Windows Process Execution of Fast Reverse Proxy (FRP) frpc.exe or frps.exe
Alerts on Windows execution of FRP components (frpc.exe/frps.exe) with FRP indicators via command line or known hashes.
sigmaWindowshigh2022-09-02Windows certutil.exe Initiates Network Connections to Common Service Ports
Alerts when certutil.exe initiates outbound network connections to ports 80, 135, 443, or 445 on Windows.
sigmaWindowshigh2022-09-02Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.
sigmaWindowshigh2022-09-01Windows Process Creation: Suspicious ShellExec_RunDLL Command-Line Usage
Detects Windows command lines containing ShellExec_RunDLL along with other suspicious execution indicators.
sigmaWindowshigh2022-09-01Windows net.exe Commands Manipulating Built-in Default Accounts (administrator/guest)
Flags net.exe/net1.exe process creation when command lines reference built-in Administrator/guest/default accounts with suspicious active/disable context.
sigmaWindowshigh2022-09-01Windows Suspicious cmd.exe Launch After net use Mounting WebDAV Share
Flags cmd.exe command lines that mount an Internet WebDAV share with net use and immediately execute content from DavWWWRoot.
sigmaWindowshigh2022-09-01Windows Process Creation: DefenderCheck.exe Execution (PUA/Signature Evasion)
Alerts on execution of DefenderCheck.exe/description to identify potential AV signature probing and evasion preparation.
sigmaWindowshigh2022-08-30Windows Network Connection from Cmstp.EXE (Outbound)
Alerts on outbound network connections initiated by cmstp.exe, which is uncommon and may indicate process misuse.
sigmaWindowshigh2022-08-30Windows: cmstp.exe Loading DLL/OCX from Suspicious Paths
Alerts when cmstp.exe loads DLL/OCX from suspicious directories on Windows.
sigmaWindowshigh2022-08-30Windows RTCore64 Service Installation via Service Control Manager (Event ID 7045)
Alerts on creation of the RTCore64 Windows service via Service Control Manager Event ID 7045.
sigmaWindowshigh2022-08-30Windows SharpLdapWhoami Execution via LDAP Whoami Methods
Flags execution of SharpLdapWhoami on Windows using LDAP-related whoami alternative method parameters.
sigmaWindowshigh2022-08-29Windows Process Creation: nimgrab.exe Execution (Nim Tool Download Behavior)
Alerts on execution of nimgrab.exe on Windows when hashes match known indicators.
sigmaWindowshigh2022-08-28Windows Network Connections by wscript/cscript Script Interpreters to Non-Local IPs
Flags wscript.exe/cscript.exe making outbound connections to non-local destination IPs.
sigmaWindowshigh2022-08-28Windows Scheduled Task Index Registry Tampering Hiding Tasks from Query Tools
Alerts on registry set events that tamper scheduled task TaskCache Tree "Index" DWORD to 0.
sigmaWindowshigh2022-08-26