Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Azure audit logs: Delegated highly privileged permissions granted for all users
Alerts on Azure audit log events where delegated permissions are granted to all users.
sigmaCloudhigh2022-07-28Windows: WinRing0 Driver Load via Image Hash and File Name Match
Alerts on Windows driver loads matching WinRing0 modules by IMPhash or expected WinRing0 filenames.
sigmaWindowshigh2022-07-26Windows: Detect SelectMyParent PPID Spoofing Tool Execution
Flags SelectMyParent.exe process creation with PPID spoofing command-line and metadata indicators on Windows.
sigmaWindowshigh2022-07-23Windows Registry: Detect DLLPathOverride Persistence in ContentIndex Natural Language
Alerts on Windows registry changes to ContentIndex Natural Language DLLPathOverride values tied to SearchIndexer.exe persistence.
sigmaWindowshigh2022-07-21Windows Registry: mpnotify SIP Provider Persistence via Winlogon
Detects registry writes to the Winlogon mpnotify location indicating potential SIP-provider persistence.
sigmaWindowshigh2022-07-21Windows Registry: LSA Extensions Multi-SZ DLL Persistence (REG_MULTI_SZ)
Alerts on registry edits to LSA extension DLL entries under LsaSrv\Extensions that can support persistence through lsass.exe loading.
sigmaWindowshigh2022-07-21Windows Registry Persistence via HtmlHelp Author Location Modification
Detects Windows registry updates to HtmlHelp Author Location paths that may be used for persistence.
sigmaWindowshigh2022-07-21Windows Registry Persistence via hhctrl CLSID InprocServer32 Default Modification
Flags registry changes to the hhctrl COM CLSID InprocServer32 (Default) to load a custom binary instead of the system hhctrl.ocx.
sigmaWindowshigh2022-07-21Windows Registry: Add Debugger Value Under Windows Error Reporting Hangs Key
Flags registry modifications adding a Debugger entry under Windows Error Reporting Hangs, a potential crash-triggered persistence technique.
sigmaWindowshigh2022-07-21Windows: PSEXESVC-Launched Child Process Running as LOCAL SYSTEM
Alerts when PSEXESVC spawns a child process running as LOCAL SYSTEM (AUTHORI/AUTORI) on the local host.
sigmaWindowshigh2022-07-21Windows PsExec Service Binary Renamed Execution via psexesvc.exe
Alerts when psexesvc.exe is executed from a non-standard path, suggesting renamed or relocated PsExec service usage.
sigmaWindowshigh2022-07-21Windows Explorer ZIP Extraction Dropping Startup Folder Shortcut
Alert on explorer.exe writing Startup-folder LNK files whose names include {0AFACED1-E828-11D1-9187-B532F1E9575D}, indicating shortcut-based persistence.
sigmaWindowshigh2022-07-21Linux Process Command-Line Indicators of Apache Spark Shell Command Injection Attempt
Alerts on Linux process creation where a bash-spawned command line contains `id -Gn ` injection-like backtick or quote patterns.
sigmahigh2022-07-20Weblog Detection of Apache Spark Shell Command Injection Payloads (?doAs=`)
Alerts on web requests containing "?doAs=`" that may indicate Spark shell command injection attempts.
sigmahigh2022-07-19Rejetto HFS HTTP request RCE exploit pattern via null-byte search and script/command payloads
Detects Rejetto HFS HTTP requests with a crafted search parameter and command/script execution indicators.
sigmahigh2022-07-19Windows UEFI Persistence: Detect wpbbin.exe Execution
Alerts on execution of C:\Windows\System32\wpbbin.exe, a potential indicator of UEFI persistence on Windows.
sigmaWindowshigh2022-07-18Windows UEFI Persistence Indicator: Creation of C:\Windows\System32\wpbbin.exe
Flags creation of C:\Windows\System32\wpbbin.exe, a potential UEFI persistence artifact.
sigmaWindowshigh2022-07-18Windows Registry Fax Device Provider ImageName changed to load external DLL
Alerts when Fax Device Providers\ImageName registry values change in a way consistent with DLL-loading persistence.
sigmaWindowshigh2022-07-17Windows Registry: User Account Changed for FAX Service
Flags registry changes that alter the FAX service’s associated user account on Windows.
sigmaWindowshigh2022-07-17Windows UAC Bypass via iscsicpl.exe DLL Search Order Hijacking (iscsiexe.dll)
Detects iscsicpl.exe loading iscsiexe.dll from outside C:\Windows, consistent with UAC bypass DLL hijacking.
sigmaWindowshigh2022-07-17