Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Execution: Suspicious PowerShell Encoded Command with Exec Bypass
Flags Windows process creations with a bypass-and-encoded PowerShell Start-Job command-line pattern linked to Mercury-related activity.
sigmahigh2022-08-26Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Alerts on Service Control Manager EventID 7045 for Sliver service installations using a known Temp-staged EXE path pattern.
sigmaWindowshigh2022-08-25Windows RegistrySet: EulaAccepted set for renamed Sysinternals tools
Flags Windows registry writes to \EulaAccepted for Sysinternals-related objects when performed by non-matching executables.
sigmaWindowshigh2022-08-24Windows Registry: Sysinternals Renamed Tool Execution Indicator via EulaAccepted Key
Flags registry writes to EulaAccepted for Sysinternals-named targets when executed by non-matching image filenames.
sigmaWindowshigh2022-08-24Windows msdt.exe Creating Files in Common Startup and Public Directories
Alerts when msdt.exe writes files to high-suspicion directories that may indicate persistence after exploitation.
sigmaWindowshigh2022-08-24Windows Named Pipe Stream Created with Known Hack Tool IMPHASHs
Alerts on Windows named file stream creation events whose IMPHASH matches common hack-tool binaries.
sigmaWindowshigh2022-08-24Windows CreateStreamHash: Suspicious Downloads From File Sharing and Paste Websites
Identifies Windows stream-hash events tied to downloads from file-sharing/paste domains with Zone-tagged payload extensions.
sigmaWindowshigh2022-08-24Windows Process Creation: Suspicious CLI NetworkProvider Addition for Credential Dumping
Alerts on Windows CLI executions that reference services\... and NetworkProvider, a pattern consistent with credential dumping via provider changes.
sigmaWindowshigh2022-08-23Windows cmd.exe Command-Line Anomaly: Missing Spaces Around /c /k /r
Flags cmd.exe invocations with suspicious missing spaces around /c, /k, or /r based on process creation CommandLine patterns.
sigmaWindowshigh2022-08-23Windows Registry Persistence Risk: TypedPaths Key Modified by Non-Explorer Processes
Alerts on changes to Explorer TypedPaths registry entries from processes other than explorer.exe.
sigmaWindowshigh2022-08-22Windows Rundll32 Masquerading: DllRegisterServer CommandLine Not Using rundll32.exe
Alerts when 'DllRegisterServer' appears in the command line while the executing image is not rundll32.exe.
sigmaWindowshigh2022-08-22Windows PUA CsExec Execution via Process Creation
Flags Windows process creation of csexec.exe (CsExec) consistent with remote execution tooling usage.
sigmaWindowshigh2022-08-22Windows Process Creation: Renamed AdFind.exe Executions
Detects renamed AdFind.exe executions using AdFind-style domain discovery command-line indicators, OriginalFileName, and known binary hashes.
sigmaWindowshigh2022-08-21Windows PowerShell Command History Disable via Remove-Module psreadline
Detects PowerShell scripts that remove psreadline with Remove-Module to suppress command history evidence.
sigmaWindowshigh2022-08-21Windows Script Dropped by Signed Applications and LOLBINs
Detects Windows legitimate/signed executables dropping script files (.ps1, .vbs, .js, etc.) to disk, indicating potential script-based abuse.
sigmaWindowshigh2022-08-21Windows Suspicious App and LOLBIN Dropping Executable Files to Disk
Alerts on Windows processes like Office/LOLBINs writing .exe/.dll and other executable-equivalent files to disk.
sigmaWindowshigh2022-08-21Windows Executable Dropping Archive Files via Common LOLBINs and Office Apps
Alerts when Office or other specified Windows binaries create archive files like .zip/.rar/.7z/.diagcab/.appx on disk.
sigmaWindowshigh2022-08-21Windows Process Creation: TruffleSnout.exe Execution
Detects execution of TruffleSnout.exe on Windows using process creation metadata.
sigmaWindowshigh2022-08-20Windows reg.exe Adds or Modifies Suspicious Registry Locations via Command Line
Alerts on reg.exe registry modifications targeting specific Windows policy, security, Defender, and credential-related paths.
sigmaWindowshigh2022-08-19Windows: Suspicious CustomShellHost.exe execution spawned by non-Explorer parent
Alerts on CustomShellHost.exe executions where explorer.exe is not the expected parent process image.
sigmaWindowshigh2022-08-19