Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Suspicious Script/Command Child Processes Spawned by ArcSOC.exe
Alerts when ArcSOC.exe launches cmd/cscript/mshta/powershell/wscript and similar interpreters, indicating potential remote code execution.
sigmaWindowshigh2025-11-25ArcSOC.exe Creates Suspicious Script/Executable Files on Windows
Alerts when ArcSOC.exe creates files with script/executable extensions such as .exe, .ps1, .aspx, or .bat.
sigmaWindowshigh2025-11-25Linux Script Interpreters Spawning Credential Scanners (trufflehog, gitleaks)
Flags Linux cases where node or bun processes launch trufflehog or gitleaks to search for secrets.
sigmaLinuxhigh2025-11-25Windows Process Creation: Bun executes bun_environment.js via node.exe
Flags node.exe spawning bun.exe with a command line containing bun_environment.js and a GitHub runner release download.
sigmahigh2025-11-25Windows Process Creation: Shai-Hulud String Indicators in Command Line
Alerts on Windows process executions whose command line includes Shai-Hulud indicator strings.
sigmahigh2025-11-25Linux Bun Runtime Execution: bun_environment.js via node-parent process
Flags /node-launched /bun executions running bun_environment.js with an external runner release download URL.
sigmahigh2025-11-25Linux Process Creation: Shai-Hulud String Indicators in Command Line
Alerts on Linux process command lines containing Shai-Hulud or SHA1HULUD indicator strings.
sigmahigh2025-11-25Windows Process Creation: File Upload Clickfix Lure via Browser to Command Execution
Alerts when browser-launched processes include clickfix-style command markers plus tool and captcha-related terms on Windows.
sigmaWindowshigh2025-11-24Windows WSASS Process Execution via WerFaultSecure.EXE
Alerts on Windows process creation showing wsass.exe running with WerFaultSecure.exe and a PID-like argument.
sigmaWindowshigh2025-11-23Linux File Creation: Filename Contains Embedded Base64 Bash Fragments
Alerts on Linux file events for filenames that appear to embed Base64-decoding bash command patterns.
sigmaLinuxhigh2025-11-22macOS Atomic Stealer FileGrabber and curl POST to exfiltrate /tmp/out.zip
Alert on macOS command lines showing FileGrabber from /tmp or curl POST exfiltration with /tmp/out.zip.
sigmahigh2025-11-22macOS File Persistence from Atomic MacOS Stealer (helper file and LaunchDaemon plist)
Flags macOS file creations used as persistence artifacts: per-user .helper files and a specific LaunchDaemon plist.
sigmahigh2025-11-22Cisco ASA WebVPN Proxy GET Requests to MacTunnel and csvrloader Paths
Alerts on proxy-observed HTTP GET requests to specific Cisco ASA WebVPN exploit-related URI stems.
sigmahigh2025-11-20Windows ClickFix/FileFix Clipboard Phishing Leading to Suspicious mshta/powershell Command Execution
Alerts on explorer.exe child process launches with clipboard markers and anti-bot/CAPTCHA-related wording indicating ClickFix/FileFix execution.
sigmaWindowshigh2025-11-19Windows Network Connection Initiated by finger.exe
Alerts on Windows network connections started by finger.exe, an unusual utility that can support remote command retrieval.
sigmaWindowshigh2025-11-19Windows DNS Queries Triggered by finger.exe
Alerts on Windows DNS queries made by finger.exe, a rarely used utility that can be abused to fetch remote commands.
sigmaWindowshigh2025-11-19Windows: Suspicious Kerberos Ticket Requests from PowerShell Using KerberosRequestorSecurityToken
Flags PowerShell command lines that reference KerberosRequestorSecurityToken and .GetRequest() for suspicious Kerberos ticket requests.
sigmaWindowshigh2025-11-18Windows svchost.exe Uncommon Command-Line Parameter Process Creation
Alerts on Windows process starts of svchost.exe that include an uncommon -k parameter format, after excluding common and benign patterns.
sigmaWindowshigh2025-11-14Windows Registry: Suspicious Space-Padded TypedPaths Details String
Alerts on registry writes to TypedPaths url1 where Details includes “#” plus unusual Unicode space padding.
sigmaWindowshigh2025-11-04Windows Registry RunMRU Path with Suspicious Space Characters and Delimiter
Alerts on RunMRU registry updates containing '#' plus excessive unusual Unicode spaces that may conceal command text.
sigmaWindowshigh2025-11-04