Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
90 rules
Windows WMIC loading JavaScript/VBScript engine libraries
Alerts on wmic.exe loading jscript.dll or vbscript.dll, a common sign of script execution via Windows Management Instrumentation.
sigmaWindowsmedium2020-10-17Windows WMIC process creation with suspicious command execution
Alerts on WMIC spawning new processes with command-line indicators of common execution/payload binaries on Windows.
sigmaWindowshigh2020-10-12Windows WMIPRVSE DLL Hijack via Network-Created wbemcomn.dll in System32\wbem
Flags wmiprvse.exe loading wbemcomn.dll from the System32\wbem directory, consistent with a WMI DLL hijack.
sigmaWindowshigh2020-10-12Windows WMI DLL Hijack via Network-placed wbemcomn.dll in System32\wbem
Alerts when System creates wbemcomn.dll in C:\Windows\System32\wbem\, consistent with WMI DLL hijack file staging.
sigmaWindowscritical2020-10-12Windows Security Log: Network Write of wbemcomn.dll in System32\wbem for WMI DLL Hijack (T1047)
Flags remote creation of wbemcomn.dll in System32\wbem associated with WMI DLL hijack activity.
sigmaWindowshigh2020-10-12Windows: Remote code execution via winrm.vbs using cscript and wmicimv2/Win32_ Create
Alerts on cscript.exe executions referencing winrm and wmicimv2/Win32_ Create with -r:http, consistent with remote code execution via winrm.vbs.
sigmaWindowsmedium2020-10-07Windows Security: Suspicious Remote Logon Using Explicit Credentials via Command-Line Tools
Flags EventID 4648 remote logons initiated by cmd/PowerShell/winrs/wmic/net/reg-style processes using explicit credentials.
sigmaWindowsmedium2020-10-05WMI scrcons.exe Loading Script and WMI DLLs via Image Load (Windows)
Alerts when scrcons.exe loads vbscript/wbem/WMI script DLLs, suggesting WMI ActiveScriptEventConsumer activity.
sigmaWindowsmedium2020-09-02Windows Security 4624 Logon for scrcons.exe Indicating Remote WMI ActiveScriptEventConsumers
Flags remote network logons involving scrcons.exe that may indicate WMI ActiveScriptEventConsumers activity.
sigmamedium2020-09-02Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
sigmaWindowshigh2020-07-14Windows Persistence Attempt via sc config or wmic COR_PROFILER (Blue Mockingbird)
Flags sc.exe sc config and wmic.exe COR_PROFILER command lines tied to wercplsupporte.dll references.
sigmahigh2020-05-14Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
sigmacritical2020-05-08Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
sigmaWindowshigh2020-03-26Zeek DCE-RPC Execution Indicators: JobAdd, Task Scheduler RPC, WMI ExecMethod, and Service Creation/Start
Detects Zeek DCE-RPC calls that match execution-related JobAdd, Task Scheduler, WMI, or service create/start operations.
sigmaNetworkmedium2020-03-19Successful Windows Account Logon via WMI (4624 with WmiPrvSE.exe)
Flags successful 4624 logons tied to WmiPrvSE.exe, indicating WMI-driven authentication on Windows.
sigmaWindowslow2019-12-04Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
sigmaWindowshigh2019-10-22Windows Shadow Copy Creation via PowerShell/pwsh/wmic/vssadmin Commands
Detects Windows processes using PowerShell/pwsh/wmic/vssadmin with shadow copy creation parameters.
sigmaWindowsmedium2019-10-22Windows WMI Backdoor in Exchange Transport Agent via WMI Event Filter Execution
Alerts when WMI-backed execution is launched under EdgeTransport.exe, excluding common Exchange and conhost false positives.
sigmaWindowscritical2019-10-11Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
sigmaWindowshigh2019-09-26Windows: WmiPrvSE.exe Spawning a Child Process
Identifies child processes created by WmiPrvSE.exe on Windows, highlighting potential WMI-based execution attempts.
sigmaWindowsmedium2019-08-15