Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Execution of HandleKatz LSASS Dumper (loader.exe)
Flags HandleKatz-style loader.exe executions that dump LSASS into obfuscated .obf files using --pid and --outfile.
sigmaWindowshigh2022-08-18Windows driver load of HackSys Extreme Vulnerable Driver (HEVD.sys) via image hash
Flags Windows systems when HEVD driver \HEVD.sys is loaded with known IMPHASH values.
sigmaWindowshigh2022-08-18Windows Malicious Driver Load by Known Hashes
Alerts on Windows driver loads matching known malicious driver hashes (MD5/SHA1/SHA256/IMPHASH).
sigmaWindowshigh2022-08-18Windows Executable Connections to Dead Drop Resolver Domains Excluding Common Browsers
Flags non-browser Windows executables making outbound connections to known dead-drop resolver domain patterns.
sigmaWindowshigh2022-08-17Windows: Detect Microsoft Office DLL sideloading via ImageLoad of outllib.dll from nonstandard path
Alerts on outllib.dll loads from non-standard locations rather than typical Microsoft Office directories.
sigmaWindowshigh2022-08-17Sysmon FileBlockExecutable event: blocked executable execution attempts on Windows
Alerts when Sysmon blocks an attempted executable execution due to FileBlockExecutable policy violations.
sigmaWindowshigh2022-08-16Windows Process Creation: mshtml.dll RunHTMLApplication Execution via Protocol Handlers
Alerts on Windows command lines invoking mshtml.dll RunHTMLApplication (via #135) with path traversal markers.
sigmaWindowshigh2022-08-14Windows DLL Sideloading: System DLL Names Loaded from Non-Standard Paths (ImageLoad)
Alerts when Windows image loads DLL names typically found in system locations, excluding common benign paths to reduce false positives.
sigmaWindowshigh2022-08-14Windows rundll32 Loading Renamed comsvcs.dll via DLL Image Load
Flags rundll32.exe loading a renamed comsvcs.dll module consistent with process memory dumping behavior on Windows.
sigmaWindowshigh2022-08-14Windows: Unusual Process Tree for wab.exe and wabmig.exe
Alert on abnormal parent/child process relationships involving wab.exe and wabmig.exe in Windows process creation logs.
sigmaWindowshigh2022-08-12Windows Process Creation: wab.exe or wabmig.exe Run from Non-Default Paths
Alerts when wab.exe or wabmig.exe run from unexpected directories on Windows.
sigmaWindowshigh2022-08-12Windows: findstr.exe LSASS keyword matching for process reconnaissance
Alert on find.exe/findstr.exe command lines containing "lsass", indicating potential LSASS-focused reconnaissance.
sigmaWindowshigh2022-08-12Windows file write events where executables save files with suspicious script/binary extensions
Alerts when common Windows system executables write files ending in suspicious extensions like .ps1, .bat, .vbs, or .hta.
sigmaWindowshigh2022-08-12Windows Malicious iphlpapi.dll Dropped in OneDrive/Teams AppData Directory
Flags creation of iphlpapi.dll in the Microsoft AppData area used by OneDrive/Teams, consistent with DLL sideloading attempts.
sigmaWindowshigh2022-08-12Webserver URI Probe for Workspace ONE Access Auth Bypass Attempt (CVE-2022-31656)
Alerts on webserver requests to Workspace ONE Access containing a URI query pattern linked to CVE-2022-31656 exploitation.
sigmahigh2022-08-12Azure AD Account Created and Deleted Shortly After Creation (Audit Logs)
Identifies successful Azure user creation and deletion in quick succession, consistent with short-lived account activity.
sigmaCloudhigh2022-08-11Windows Registry: Change to Services\WinSock2\Parameters\AutodialDLL for DLL Persistence
Alerts on registry changes to AutodialDLL under WinSock2 parameters that may enable DLL-based persistence.
sigmaWindowshigh2022-08-10Windows Registry App Paths Default Property Change Using Suspicious Values
Alerts on Windows App Paths registry edits to (Default)/Path with suspicious binaries, scripts, or temp/public locations.
sigmaWindowshigh2022-08-10Windows Startup Folder File Creation with Suspicious Script/Executable Extensions
Alerts on creation of startup-folder files with script/executable extensions commonly used for logon persistence on Windows.
sigmaWindowshigh2022-08-10Linux auditd: BPFDoor .pid or .lock file access in /var/run
Alerts on auditd-monitored access to specific /var/run .pid and .lock files associated with BPFDoor-style behavior.
sigmaLinuxhigh2022-08-10