Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Registry Event Log Tampering by Disabling WINEVT Channel Enabled Key
Flags registry changes that set WINEVT channel Enabled to 0x00000000 to disable Windows event logging.
sigmaWindowshigh2022-07-04Windows UAC Bypass via IDiagnosticProfileUAC Triggered from DllHost.exe
Flags elevated process creation where DllHost.exe launches using the specific IDiagnosticProfileUAC /Processid value.
sigmaWindowshigh2022-07-03Windows: DllHost.exe creates a System32 DLL for UAC bypass via IDiagnosticProfileUAC
Alerts when dllhost.exe creates a System32 .dll consistent with IDiagnosticProfileUAC UAC bypass behavior.
sigmaWindowshigh2022-07-03Windows: Suspicious LSASS handle access via svchost.exe call trace to seclogon.dll
Flags svchost.exe attempting LSASS access (granted access 0x14c0) with seclogon.dll in the call trace.
sigmaWindowshigh2022-06-29Windows: assoc.exe Changes File Extension Handler to exefile
Alerts on cmd.exe running assoc to set file extension handlers to exefile, indicating possible persistence via file associations.
sigmaWindowshigh2022-06-28Windows Process Creation: bitsadmin Downloads Files to Suspicious Directories
Flags bitsadmin.exe file downloads that target suspicious folders using /transfer, /create, and /addfile command-line parameters.
sigmaWindowshigh2022-06-28Windows Process Creation: BITSAdmin Downloading File with Suspicious Extension
Flags bitsadmin.exe commands that transfer or add files with suspicious extensions based on process creation command-line content.
sigmaWindowshigh2022-06-28Windows BITSAdmin Downloads from File-Sharing Domains
Alerts on BITSAdmin downloads from popular file-sharing domains when transfer/create/addfile command-line flags are present.
sigmaWindowshigh2022-06-28Windows Process Creation: bitsadmin Download Using Direct IP URL
Alerts when bitsadmin.exe is used to download via a direct IP address in the command line on Windows.
sigmaWindowshigh2022-06-28Windows attrib.exe sets hidden system file attribute (+s) on suspicious paths and script/executable extensions
Flags attrib.exe usage with +s to mark .exe/.dll and script files in public/temp/user-writable locations as system files.
sigmaWindowshigh2022-06-28PowerShell disables or removes ETW Trace via Set-EtwTraceProvider or Remove-EtwTraceProvider
Flags PowerShell commands that remove or disable ETW trace providers to impair Windows telemetry.
sigmaWindowshigh2022-06-28Windows BITS Transfer Job Download to Suspicious File Paths
Flags new Windows BITS transfer jobs that save downloaded files into predefined suspicious paths.
sigmaWindowshigh2022-06-28Windows BITS Client Downloads From File-Sharing Domains
Alerts on Windows BITS transfers (EventID 16403) that download from known file-sharing/content hosting domains.
sigmaWindowshigh2022-06-28Azure AD Sign-ins from Non-Compliant Devices
Alert on Entra ID sign-ins originating from devices flagged as non-compliant.
sigmaCloudhigh2022-06-28Azure Audit Logs: User Added to Global or Device Administrator Roles
Alerts when Azure AD role-management events add users to Global or Device Administrator roles.
sigmaCloudhigh2022-06-28Azure AD/Entra Audit Logs: Device Registration Policy Changes
Alerts on Azure audit log events that set or modify the device registration policy.
sigmaCloudhigh2022-06-28Windows dllhost.exe Launched With No Command-Line Arguments
Alerts on dllhost.exe being executed with no command-line arguments, a rare pattern that may indicate stealthy or injected activity.
sigmaWindowshigh2022-06-27Windows HandleKatz: Duplicate LSASS Handle via Process Access with Handle Duplication Rights
Flags HandleKatz-style behavior duplicating an existing LSASS handle using PROCESS_DUP_HANDLE and ntdll.dll call trace.
sigmaWindowshigh2022-06-27Windows WerFault LSASS Memory Dump File Creation
Flags WerFault dump creation where the dump filename suggests it contains LSASS memory.
sigmaWindowshigh2022-06-27Windows: Potential Process Injection via Msra.exe Spawning Suspicious Child Processes
Flags Msra.exe spawning suspicious tools that may indicate process injection or post-exploitation activity on Windows.
sigmaWindowshigh2022-06-24