Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
117 rules
Windows: Suspicious Process Execution of hostname.exe
Flags execution of hostname.exe from process creation events on Windows for discovery activity.
sigmaWindowslow2022-01-01SharpHound RPC Firewall Recon: Remote Mapping and Group Membership Enumeration
Alerts on RPC Firewall EventID 3 for SharpHound-style discovery RPC calls to interface UUID with OpNum 12.
sigmahigh2022-01-01SharpHound Account Recon via RPC Firewall Block (OpNum 2, Interface UUID)
Alerts on RPC Firewall EventID 3 with the Interface UUID and OpNum used by SharpHound for account discovery.
sigmahigh2022-01-01RPC Firewall Alerts for SASec Scheduled Task Discovery (SASec)
Identifies RPC Firewall alerts for SASec interface calls related to scheduled task discovery.
sigmahigh2022-01-01PowerShell Credential Discovery via Recursive File Search and Select-String
Flags PowerShell script blocks that recursively list files and run select-string pattern searches, indicative of credential hunting.
sigmaWindowsmedium2021-12-19Windows Sysmon Discovery Attempt via Findstr.exe Default Driver Altitude (385201)
Alerts on findstr/find.exe executions containing 385201, consistent with using Sysmon default driver altitude for discovery.
sigmaWindowshigh2021-12-16PowerShell Security Software Discovery Using get-process Piped to where-object (Windows)
Flags PowerShell scripts that enumerate processes and filter results for security software by vendor/product keywords.
sigmaWindowsmedium2021-12-16PowerShell ScriptBlock Enumeration of AD Group Membership and User Attributes (Windows)
Flags PowerShell script blocks querying AD group membership and user details for discovery of privileged directory information.
sigmaWindowslow2021-12-15PowerShell Module: Get-SmbShare Used for SMB Share Discovery
Detects PowerShell module usage of Get-SmbShare to enumerate SMB shares across networked systems.
sigmaWindowslow2021-12-15PowerShell module enumeration of AD principals via get-ADPrincipalGroupMembership
Flags PowerShell module usage of Get-ADPrincipalGroupMembership and Get-ADUser with -pr -f patterns indicative of AD discovery.
sigmaWindowslow2021-12-15Windows PUA: Suspicious Active Directory enumeration using AdFind.exe flags
Flags AdFind.exe processes that look like Active Directory discovery via password policy and object enumeration options.
sigmaWindowshigh2021-12-13Windows Process Discovery via wmic.exe "group" Flag
Flags wmic.exe process executions querying local group information via a "group" command-line argument.
sigmaWindowslow2021-12-12PowerShell Suspicious Discovery of Local Groups via Get-LocalGroup Cmdlets
Flags PowerShell commands that enumerate local groups and group membership, including WMI/CIM queries for Win32 group data.
sigmaWindowslow2021-12-12PowerShell Local Group Discovery via Get-LocalGroup and Get-LocalGroupMember (Windows)
Identifies PowerShell commands enumerating local groups and their members, indicating potential local permission discovery.
sigmaWindowslow2021-12-12Windows Process Discovery via tasklist Command Execution
Alerts on Windows executions of tasklist.exe used for running process discovery.
sigmainformational2021-12-11Windows Process Creation: Nmap/Zenmap (nmap.exe or zennmap.exe) Execution
Flags Windows execution of Nmap/Zenmap (nmap.exe or zennmap.exe) used for remote service discovery.
sigmaWindowsmedium2021-12-10Windows Net.exe Network Connections Discovery via Use Sessions Query
Flags net.exe/net1.exe commands using 'use sessions' to enumerate network connection/session information.
sigmaWindowslow2021-12-10Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Alerts when SharpView.exe runs with command-line indicators of AD and network discovery/enumeration activity.
sigmaWindowshigh2021-12-10PowerShell Get-NetTCPConnection Network Connection Discovery (Windows)
Detects PowerShell use of Get-NetTCPConnection to enumerate TCP network connections for discovery.
sigmaWindowslow2021-12-10Windows Process Creation: Suspicious Network Configuration and Discovery Commands
Alerts on Windows command-line usage of network configuration and discovery tools (ipconfig, netsh, arp, nbtstat, net config, route print).
sigmaWindowslow2021-12-07