Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
Exchange Management: Certificate CSR exported to webserver or .aspx-named path
Flags Exchange CSR export commands that write request files to C$ and web-root paths or use an .aspx filename.
sigmaWindowscritical2021-08-23Fortinet WAF: Detect POST to /api/v2.0/user/remoteserver.saml (CVE-2021-22123 attempt)
Flags suspicious Fortinet WAF HTTP POST requests targeting a remoteserver.saml API query pattern consistent with CVE-2021-22123 exploitation.
sigmacritical2021-08-19Windows whoami.exe Renamed Execution via Mismatched OriginalFileName
Alerts when a renamed process still reports OriginalFileName as whoami.exe on Windows.
sigmaWindowscritical2021-08-12Windows SystemNightmare Exploitation Attempt via PrintNightmare Command Lines
Alerts on Windows process command lines matching SystemNightmare/PrintNightmare exploitation indicators that may enable LOCAL_SYSTEM shell access.
sigmacritical2021-08-11Exchange ProxyLogon activity: IIS POST SetObject Reset VirtualDirectory requests
Alerts on successful POSTs to ECP DDIService SetObject resetting a VirtualDirectory with a '$' username suffix.
sigmacritical2021-08-10Microsoft Exchange: Mailbox export to UNC path or .aspx filename with possible role assignment
Flags Exchange mailbox export commands targeting UNC paths with .aspx or granting the Mailbox Import Export role.
sigmaWindowscritical2021-08-09Windows Exchange Management: Set-OabVirtualDirectory after ProxyLogon exploitation
Flags Exchange management command lines invoking Set-OabVirtualDirectory with suspicious external URL/script injection patterns.
sigmaWindowscritical2021-08-09Successful ProxyShell-like Exchange exploitation via autodiscover.json and PowerShell/MAPI paths
Flags Exchange-targeted web requests with /autodiscover.json plus exploit URI fragments returning 200/301.
sigmacritical2021-08-09Windows Named Pipe Creation Matching Cobalt Strike Malleable C2 Profile Patterns
Alerts on Windows named pipe creation with PipeName patterns consistent with Cobalt Strike Malleable C2 behavior.
sigmaWindowscritical2021-07-30Windows Hacktool Execution Indicators for SMB/NTLM Relay and Potato-Style Privilege Escalation
Alerts on Windows execution of common SMB/NTLM relay and “Potato” privilege escalation hacktool indicators via process creation fields.
sigmaWindowscritical2021-07-24Windows Registry Modification Indicative of CVE-2021-31979 and CVE-2021-33771 Exploitation
Flags registry changes to targeted COM InprocServer32 CLSID paths tied to CVE-2021-31979/33771 exploitation behavior on Windows.
sigmacritical2021-07-16Windows file event detection for CVE-2021-31979 and CVE-2021-33771 exploitation artifact paths
Flags Windows file events where the target filename matches paths tied to CVE-2021-31979/CVE-2021-33771 exploitation patterns.
sigmacritical2021-07-16Windows Process Creation: Serv-U CVE-2021-35211 Exploitation Command Pattern
Alerts on Windows process commands that combine 'whoami' with Serv-U-specific execution path and temp batch patterns tied to CVE-2021-35211.
sigmacritical2021-07-14Windows Registry: Flag Print Driver Registry Paths for QMS 810 and mimikatz
Detects registry TargetObject entries containing QMS 810 or mimikatz-related printer driver names under Windows print environments.
sigmacritical2021-07-04Windows Print Spooler Exploitation Indicators: UNIDRV.DLL and mimispool Driver Loads (Event ID 316)
Flags Windows Print Spooler Event ID 316 entries containing UNIDRV/mimispool-related keywords indicative of CVE-2021-1675 exploitation.
sigmacritical2021-07-01Antivirus detections of PrinterNightmare PoC file creation path on Windows
Alerts on antivirus events where filenames include the Windows spooler driver x64 directory path, excluding Symantec submission messages.
sigmacritical2021-07-01Windows File Events: PoC Filename Pattern for CVE-2021-1675 Spooler Exploitation
Flags Windows file events referencing a specific spooler driver path pattern associated with CVE-2021-1675 PoC activity.
sigmacritical2021-06-29Windows Execution of PurpleSharp HackTool by Image Name or Executable Metadata
Alerts on process creation events consistent with running PurpleSharp.exe on Windows.
sigmaWindowscritical2021-06-18BabyShark HackTool Proxy C2 URL Pattern via momyshark?key=
Alerts on proxy URIs containing the BabyShark agent default "momyshark?key=" query pattern.
sigmaWebcritical2021-06-09Windows Rundll32 Loads DLL Export StartNodeRelay (F-Secure C3)
Flags rundll32.exe launching a DLL that references the StartNodeRelay export in its command line.
sigmaWindowscritical2021-06-02