Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Windows: tar.exe Archive Extraction Using -x Flag
Flags Windows process executions of tar.exe with -x to extract compressed archives.
sigmaWindowslow2023-12-19Windows tar.exe Used to Create Compressed Archives
Flags tar.exe (or bsdtar) command lines using -c/-r/-u to create or update compressed archives on Windows.
sigmaWindowslow2023-12-19Windows WMIC System Information Discovery via WMI Command-Line Queries
Flags WMIC command-line queries that pull OS, hardware, disk, memory, BIOS, and GPU details while excluding VMware Tools discovery scripts.
sigmalow2023-12-19Windows ImageLoad: Uncommon Process Loads RstrtMgr.dll (Restart Manager)
Alerts on non-standard processes loading RstrtMgr.dll using Windows image load telemetry.
sigmaWindowslow2023-11-28Okta: Access to /reports/password-health endpoint outside expected Admin Console use
Flags requests to Okta Password Health report endpoints (/reports/password-health/*) for threat hunting.
sigmalow2023-10-25Windows PowerShell EnableScripts Policy Enabled via Registry DWORD
Flags registry changes that enable PowerShell script execution via the EnableScripts policy (DWORD 0x00000001).
sigmaWindowslow2023-10-18Windows MSSQL Failed Logon (Event ID 18456) Detection
Alerts on MSSQL-related failed login attempts (Event ID 18456) captured in Windows application logs.
sigmaWindowslow2023-10-11Windows ScreenConnect RMM System Command Execution via cmd.exe
Flags cmd.exe launched by ScreenConnect.ClientService.exe with a TEMP\ScreenConnect command-line path.
sigmaWindowslow2023-10-10Windows: ScreenConnect Temporary File Creation in ConnectWiseControl Temp
Flags file writes to ScreenConnect’s ConnectWiseControl\Temp staging directory from ScreenConnect.WindowsClient.exe.
sigmaWindowslow2023-10-10Windows Application: ScreenConnect RMM File Transfer Activity (Event 201)
Flags ScreenConnect RMM file transfer events on Windows based on provider name, Event ID 201, and transfer action text.
sigmaWindowslow2023-10-10Windows ScreenConnect Remote Command Execution (EventID 200)
Detects ScreenConnect command execution on Windows by matching EventID 200 with an 'Executed command of length' message.
sigmaWindowslow2023-10-10Windows Service Registry Key ReadControl Access (Event ID 4663)
Flags READ_CONTROL access requests to service registry keys (\SYSTEM\ControlSet\Services\) via Windows Security Event 4663.
sigmaWindowslow2023-09-28Windows Registry Scheduled Task Cache Key Creation Detection
Flags registry event activity under Scheduled TaskCache indicating scheduled task creation or updates on Windows.
sigmalow2023-09-27Windows Scheduled Task File Creation Activity (File Event)
Flags file creation under Windows scheduled task directories that may indicate new scheduled task persistence.
sigmalow2023-09-27Windows File Access to .reg and .hive Backups by Uncommon Applications
Alerts on access to .hive/.reg files from less-common application paths on Windows.
sigmalow2023-09-15Windows: Headless Chromium Browser Execution via --headless
Alerts on headless Chromium-based browser launches on Windows using the "--headless" command-line flag.
sigmaWindowslow2023-09-12Windows File Creation of .dmp/.hdmp/ .dump Crash Memory Dumps
Identifies Windows file creations of .dmp/.dump/.hdmp files that may indicate memory dump generation.
sigmalow2023-09-07Windows File Deletion: Remove Zone.Identifier Alternate Data Stream
Alerts on Windows deletions of the Zone.Identifier ADS, which attackers may remove to evade zone-based security controls.
sigmalow2023-09-04Windows: Detect WinRAR Creating .rev Files Associated with CVE-2023-40477
Alert on .rev file creation tied to WinRAR/Explorer on Windows as an indicator of potential CVE-2023-40477 exploitation.
sigmalow2023-08-31Linux Process Discovery of Container Environment via ls -i on / Directory
Detects Linux commands that list inode information for '/' to probe whether execution is occurring inside a container.
sigmaLinuxlow2023-08-23