Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Security Mitigations: Unsigned DLL Blocked from User-Writable Paths
Alerts on blocked unsigned DLL loads targeting public, downloads, desktop, or temp directories in Windows Security Mitigations logs.
sigmaWindowshigh2022-08-03Windows Command-Line Tools Performing Web POST Exfiltration via IWR/curl/wget
Identifies PowerShell/curl/wget commands on Windows that use POST-style web requests combined with data-dumping or discovery payloads.
sigmaWindowshigh2022-08-02Windows PowerShell Invoke-WebRequest Download to Suspicious Paths
Alert when PowerShell uses Invoke-WebRequest/aliases with download flags and targets suspicious file locations.
sigmaWindowshigh2022-08-02Windows: Detect VMwareXferlogs.exe Executed from Non-default Path
Alert on VMwareXferlogs.exe launching from an unexpected directory, a potential DLL sideloading technique on Windows.
sigmaWindowshigh2022-08-02Windows mpclient.dll Sideloading via MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when mpclient.dll is loaded by MpCmdRun.exe or NisSrv.exe outside known Windows Defender directories.
sigmaWindowshigh2022-08-02Windows: Potential DLL sideloading via VMwareXferlogs loading glib-2.0.dll from non-standard path
Alerts on VMwareXferlogs.exe loading glib-2.0.dll from outside the default VMware directory.
sigmaWindowshigh2022-08-02Windows Code Integrity blocks unsigned DLL loads into MpCmdRun.exe and NisSrv.exe
Flags security-mitigations events where MpCmdRun or NisSrv are prevented from loading unsigned DLLs.
sigmaWindowshigh2022-08-02Windows Registry Set to Disable Windows Defender Components
Flags registry changes that turn off Windows Defender protections via Defender and Security Center policy keys.
sigmaWindowshigh2022-08-01Windows Registry: Attachment Manager policy tampering via Attachments settings values
Detects registry changes to Windows Attachment Manager policy values that can disable or alter download safety controls.
sigmaWindowshigh2022-08-01Windows Registry Tampering: Attachment Manager Associations Default File Type Risk and LowRiskFileTypes
Flags Windows registry changes to Attachment Manager associations that set DefaultFileTypeRisk and modify LowRiskFileTypes.
sigmaWindowshigh2022-08-01Windows Registry Change Disabling WinDefend Service (WinDefend Start=4)
Flags registry changes that set WinDefend service Start to 0x4, indicating potential defensive impairment.
sigmaWindowshigh2022-08-01Windows Registry AutoLogger Session Disable/Start Tampering via Event Log Targets
Alerts when registry changes disable or stop AutoLogger sessions for EventLog-* or Defender by setting Enabled/Start to 0x0.
sigmaWindowshigh2022-08-01Windows reg.exe deletes service registry keys using the delete flag
Alerts on reg.exe command lines that delete entries under the Windows services registry path.
sigmaWindowshigh2022-08-01Windows Defender mpclient.dll Side-loading: MpCmdRun.exe or NisSrv.exe from Non-Default Paths
Alerts when MpCmdRun.exe or NisSrv.exe runs from non-default directories, a common indicator of possible mpclient.dll sideloading.
sigmaWindowshigh2022-08-01Windows ISO File Creation in User Temp and Outlook Cache Folders
Alerts on creation of .iso files in Windows AppData temp or Outlook cache paths.
sigmaWindowshigh2022-07-30Windows DLL Search Order Hijack via Space in System Directory Paths
Alerts on .dll events targeting Windows system paths with an extra space, indicative of DLL search order hijacking.
sigmaWindowshigh2022-07-30Windows Sysmon Driver Altitude Registry Changes
Identifies registry writes that change the Sysmon instance altitude value, which can disrupt Sysmon loading at boot.
sigmaWindowshigh2022-07-28Windows schtasks Scheduled Task Create/Modify Running as SYSTEM
Alerts on Windows schtasks task create/modify commands that set the run account to NT AUTHORITY\SYSTEM.
sigmaWindowshigh2022-07-28Windows: Suspicious Scheduled Task Modification via schtasks /Change /TN
Flags schtasks.exe executions that modify existing scheduled tasks (/Change /TN) using suspicious locations and command-line payload tooling.
sigmaWindowshigh2022-07-28Azure Audit Logs: Admin-initiated App Role Assignments and Privileged Delegated Permissions
Alerts on Azure audit events where an admin grants app roles to a service principal, enabling privileged application access.
sigmaCloudhigh2022-07-28