Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Initiated Connections to Ngrok Domains
Alerts when a Windows process initiates an outbound connection to ngrok domain hostnames, which may indicate staging or C2 activity.
sigmaWindowshigh2022-07-16Windows Scheduled Task Creation Triggered Once at 00:00 Using Scripted Commands
Alerts on suspicious schtasks.exe task creation for a one-time 00:00 run with embedded script/command execution strings.
sigmaWindowshigh2022-07-15Sysmon DNS Query for anonfiles.com Domain
Flags Windows Sysmon DNS queries referencing anonfiles.com to support detection of suspicious data staging.
sigmaWindowshigh2022-07-15Windows Suspicious Service Creation via sc.exe or PowerShell New-Service with Abnormal Binary Paths
Flags service creation commands (sc.exe/New-Service) when the specified binary path includes suspicious directories or script/loader utilities.
sigmaWindowshigh2022-07-14MSSQL sp_procoption Startup Execution Set/Clear via Application Log EventID 33205
Alerts on MSSQL sp_procoption being set or cleared for automatic startup execution via EXEC (EventID 33205).
sigmaWindowshigh2022-07-13Windows/MSSQL: Detect ALTER SERVER AUDIT or DROP SERVER AUDIT executions
Alerts on MSSQL ALTER/DROP SERVER AUDIT statements that disable or delete server audit coverage.
sigmaWindowshigh2022-07-13Windows MSSQL: Add Member to sysadmin Server Role (EventID 33205)
Alerts on MSSQL EventID 33205 when an ALTER SERVER ROLE command adds a member to the sysadmin role.
sigmaWindowshigh2022-07-13Windows Registry: Hidden User via Winlogon SpecialAccounts Userlist Value 0
Alerts on Windows registry updates that set Winlogon SpecialAccounts Userlist to DWORD 0 to hide users.
sigmaWindowshigh2022-07-12Windows: Base64-Encoded PE “MZ” Header Present in Command Line
Alerts when Windows command lines include Base64 strings matching a PE “MZ” header.
sigmaWindowshigh2022-07-12Windows: Local user creation via net.exe with expires:never
Flags net.exe user add commands that set expires:never for local account persistence.
sigmaWindowshigh2022-07-12Windows: Detect Suspicious mofcomp.exe Execution from Scripts or Temp Paths
Flags mofcomp.exe runs spawned by script interpreters or using temp/AppData paths, with exclusions for WmiPrvSE .mof-related activity.
sigmaWindowshigh2022-07-12Windows MSSQL xp_cmdshell Setting Change (EventID 15457)
Flags MSSQL xp_cmdshell setting changes using Windows application EventID 15457 events containing 'xp_cmdshell'.
sigmaWindowshigh2022-07-12Windows MSSQL xp_cmdshell Command Execution via Application Event 33205
Alerts when SQL Server xp_cmdshell is invoked to execute commands, using Windows application EventID 33205 data.
sigmaWindowshigh2022-07-12Windows PowerShell: Detect Command Lines with Suspicious UTF-16 Base64 Obfuscation Patterns
Alerts on PowerShell command lines containing suspicious UTF-16/Base64 obfuscation fragments indicative of hidden script logic.
sigmaWindowshigh2022-07-11Azure Audit Logs: App Granted Microsoft Graph/Exchange/SharePoint/Azure AD Permissions
Alerts on Azure AD audit log entries where an app/service principal is granted delegated or app-role permissions to Microsoft services.
sigmaCloudhigh2022-07-10Linux Triple Cross eBPF rootkit install commands via sudo tc on enp0s3
Flags sudo tc commands using qdisc/filter syntax and enp0s3 consistent with eBPF rootkit installer behavior.
sigmaLinuxhigh2022-07-05Linux process execution of execve_hijack via sudo
Alerts when /sudo spawns a process whose command line includes execve_hijack.
sigmaLinuxhigh2022-07-05Linux eBPF Backdoor File Persistence via cron.d and sudoers.d (ebpfbackdoor)
Detects Linux creation of "ebpfbackdoor" files in cron.d/sudoers.d, indicating likely persistence via an eBPF backdoor.
sigmaLinuxhigh2022-07-05Linux eBPF Rootkit Activity: File Creation of /tmp/rootlog
Detects creation of /tmp/rootlog on Linux, a marker used by the TripleCross rootkit to track backdoor state.
sigmaLinuxhigh2022-07-05Windows Registry Changes Disabling Windows Defender Event Log Channel
Detects registry changes that disable the Windows Defender Operational event log channel by setting its Enabled DWORD to 0.
sigmaWindowshigh2022-07-04