Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Azure Entra Audit Logs: Temporary Access Pass Method Added to an Account
Flags admin registration of a temporary access pass method in Azure audit logs for user accounts.
sigmaCloudhigh2022-08-10Windows Registry Persistence via MyComputer \"Default\" Value Modification
Detects changes to Explorer\MyComputer (Default) registry value that can redirect a launched binary for persistence.
sigmaWindowshigh2022-08-09Windows file creation for SharpHound/BloodHound collection output filenames
Flags SharpHound/BloodHound default collection export files (zip and multiple JSON datasets) from Windows file events.
sigmaWindowshigh2022-08-09Azure Entra PIM Role Setting Changes in Audit Logs
Alerts on Azure PIM role setting update events recorded in audit logs.
sigmaCloudhigh2022-08-09Azure PIM Alert Setting Disabled (Audit Log Message Detection)
Flags Azure audit log events where PIM alerts are disabled (message: "Disable PIM Alert").
sigmaCloudhigh2022-08-09Azure PIM Approval or Denial Recorded in Audit Logs
Flags Azure PIM elevation requests that are approved or denied in audit logs for investigation.
sigmaCloudhigh2022-08-09Windows SafeBoot Registry Key Deletion via reg.exe Command-Line
Flags reg.exe deleting the \SYSTEM\CurrentControlSet\Control\SafeBoot registry key via command line.
sigmaWindowshigh2022-08-08Windows mshta.exe launched with URL-based arguments (http/https/ftp)
Alerts when mshta.exe is executed with HTTP/HTTPS/FTP URLs in the command line, consistent with remote HTA execution.
sigmaWindowshigh2022-08-08Windows Registry RDP Terminal Services Sensitive Settings Tampering
Flags Windows registry changes to sensitive RDP/Terminal Services settings such as shadowing, remote assistance, security, and InitialProgram.
sigmaWindowshigh2022-08-06Azure Audit Logs: User Added to Privileged Eligibility Role
Alerts on Azure audit log events indicating a user was added as an eligible or permanent member to a privileged role.
sigmaCloudhigh2022-08-06Windows Exploit Guard Controlled Folder Access: Added Allowed Application for Blocked Path
Alerts when an app is added to Exploit Guard’s AllowedApplications list to bypass controlled folder restrictions for risky paths.
sigmaWindowshigh2022-08-05Windows Registry: Exploit Guard ProtectedFolders Value Deleted
Alerts on deletion of registry values under Exploit Guard Controlled Folder Access ProtectedFolders.
sigmaWindowshigh2022-08-05Windows Process Creation: wusa.exe Cab Extraction From Suspicious Directory Paths
Flags wusa.exe with /extract: originating from common temp/public paths, a potential CAB-based payload unpacking behavior.
sigmaWindowshigh2022-08-05Windows Process Creation: Remove-MpPreference Used to Tamper Windows Defender Settings
Flags process executions that call Remove-MpPreference with Defender tampering-related parameters.
sigmaWindowshigh2022-08-05Windows PowerShell ScriptBlock: Remove-MpPreference Tampering of Defender Configuration
Detects PowerShell commands removing Defender preferences via Remove-MpPreference with additional Defender setting indicators.
sigmaWindowshigh2022-08-05Windows Suspicious File Creation in AppData Outside Common Subdirectories
Alerts on new .exe/.dll/.ps1/.lnk and other files created under unusual AppData locations outside Local/LocalLow/Roaming.
sigmaWindowshigh2022-08-05Windows Defender Exploit Guard Tamper via Controlled Folder Access AllowedApplications or ProtectedFolders Changes
Alerts on Windefend EventID 5007 when Exploit Guard ProtectedFolders or AllowedApplications lists are modified.
sigmaWindowshigh2022-08-05Azure Audit Logs: Removal of Privileged Role Eligible Members
Flags Azure audit log events indicating bulk removal of eligible members from privileged roles.
sigmaCloudhigh2022-08-05Windows RDP Tunneling Using plink.exe on Local Port 3389
Alert on plink.exe command lines referencing 127.0.0.1:3389 or port 3389, suggesting potential RDP tunneling on Windows.
sigmaWindowshigh2022-08-04Windows Suspicious IIS Module Registration via w3wp.exe, appcmd.exe, and PowerShell/gacutil
Flags w3wp.exe-launched appcmd.exe module registrations involving PowerShell publication or gacutil GAC installation.
sigmaWindowshigh2022-08-04