Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Linux Process Recon: Find SUID/htpasswd Files via Command-Line Patterns
Flags Linux command-line reconnaissance patterns for .htpasswd discovery and setuid (-perm -4000) file enumeration.
sigmaLinuxhigh2022-06-20Linux Shell History File Deletion via rm/unlink/shred
Alert on Linux command-line history file deletions using rm/unlink/shred targeting bash/zsh history files.
sigmaLinuxhigh2022-06-20Windows Registry: New W32Time TimeProvider DllName Values Set Under Services\W32Time\TimeProvider
Alerts on new or changed W32Time TimeProvider DllName registry values under Services\W32Time\TimeProvider.
sigmaWindowshigh2022-06-19Windows: Chromium-Based Browser Launched via Script Host with --load-extension
Flags Windows process creation where Chromium browsers are spawned with --load-extension= from common script/LOLBins parents.
sigmaWindowshigh2022-06-19Windows File Events: Flag Files With Double Extensions (e.g., .docx.exe)
Alerts on Windows filenames that look like double extensions, including .rar.exe/.zip.exe masquerading patterns.
sigmaWindowshigh2022-06-19Windows: msdt.exe Loads sdiageng.dll via Image Load Events
Flags msdt.exe image-load events that load sdiageng.dll, a behavior commonly associated with DLL side-loading abuse.
sigmaWindowshigh2022-06-17Azure AD Sign-ins Using Legacy Authentication Client Applications
Alerts on Azure sign-ins using legacy protocol client apps (IMAP/POP3/SMTP/EWS/ActiveSync), which may indicate risky authentication usage.
sigmaCloudhigh2022-06-17Windows: FakeUpdates/SocGholish execution via wscript loading a zip-based update script
Flags wscript launched from Temp update .js within a .zip to spawn cmd.exe or PowerShell on Windows.
sigmahigh2022-06-16Windows conhost.exe Path Traversal in Process Command Line
Detects Windows conhost.exe command lines containing '/../../' path traversal indicators.
sigmaWindowshigh2022-06-14Web Server GET Requests Containing SSTI Payload Strings (Server-Side Template Injection)
Flags GET requests containing SSTI probe strings in web access logs when the response is not 404.
sigmaWebhigh2022-06-14Windows msdt.exe execution using PCWDiagnostic.xml answer file
Alerts on msdt.exe launched with PCWDiagnostic.xml and an answer-file argument, excluding cases from pcwrun.exe.
sigmaWindowshigh2022-06-13Windows: Indirect execution of pcwrun.exe using path traversal-style command line content
Detects pcwrun.exe spawning with '../' in the command line, indicating potential indirect execution abuse.
sigmaWindowshigh2022-06-13Windows Registry Custom File Open Handler Executes PowerShell
Alerts when a registry shell open handler is created to run PowerShell with -command.
sigmaWindowshigh2022-06-11Windows Process: Notepad++ GUP (GUP.exe) Download Execution via -unzipTo and URL
Detects Notepad++ GUP.exe downloading over HTTP initiated by a non-Notepad++ parent process.
sigmaWindowshigh2022-06-10Microsoft BITS Proxy Requests to Uncommon Server IP Hosts
Identifies Microsoft BITS proxy connections where the destination host ends with a single-digit, indicating uncommon IP-style addressing.
sigmaWebhigh2022-06-10Windows: Adplus.exe Execution with Memory Dump and Command Options
Alerts on Windows executions of Adplus.exe with memory-dump and inline command parameters.
sigmaWindowshigh2022-06-09Windows: ISO Image Opened by Archiver Utilities (WinRAR/7-Zip/PeaZIP)
Alerts when WinRAR/7-Zip/PeaZIP spawns ISO image tools, a pattern consistent with archive-delivered ISO payloads.
sigmaWindowshigh2022-06-07Detect DNS Queries to OAST Callback and Interaction Service Domains
Detects DNS lookups to common OAST/callback domains that may indicate SSRF-style or blind vulnerability validation.
sigmaNetworkhigh2022-06-07Windows Process Creation: Renamed Plink (plink.exe) with SSH Port Forwarding Flags
Alerts on renamed Plink executions using SSH port forwarding flags in Windows process creation logs.
sigmaWindowshigh2022-06-06Webserver: Suspicious Windows Path Strings in URI Query
Alerts when a web URI query contains encoded or plain Windows path strings indicative of possible exfiltration or webshell behavior.
sigmaWebhigh2022-06-06