Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: ManageEngine SupportCenter Plus msiexec.exe Dropped in bin (CVE-2021-44077 POC)
Alerts on msiexec.exe being created in the SupportCenterPlus bin folder on Windows.
sigmahigh2022-06-06Windows Office Startup Folder File Creation with Uncommon Extension
Detects unusual-extension files created in Word/Excel startup folders on Windows, potentially supporting automatic Office loading.
sigmaWindowshigh2022-06-05Java Payload Indicators in Web Server Logs
Alerts when web access logs contain Java payload-like strings indicating possible injection or runtime execution attempts.
sigmaWebhigh2022-06-04Windows Process Creation: Renamed msdt.exe Execution
Flags Windows process creation where OriginalFileName is msdt.exe and the executable appears to be a renamed copy.
sigmaWindowshigh2022-06-03Python Process Spawning a Pretty TTY via pty.spawn on Windows
Flags Windows python executions whose command line imports pty and calls pty.spawn to create a pseudo-terminal.
sigmaWindowshigh2022-06-03Linux Java Process Launching Suspicious Shell and Scripting Children
Alerts when a Java parent process launches shell or downloader/scripting tools on Linux.
sigmaLinuxhigh2022-06-03Linux process creation: Confluence Java spawning script or download utilities
Alerts when Confluence’s Java process on Linux spawns shell or scripting/utilities, consistent with potential CVE-driven command execution.
sigmahigh2022-06-03Windows Process Creation: BrowserCore.exe Renamed Execution for Azure Token Theft
Flags renamed BrowserCore.exe executions by matching OriginalFileName while the process image ends with BrowserCore.exe.
sigmaWindowshigh2022-06-02Windows Office Startup Folder File Drop for Persistence via Office Documents
Alerts when Office documents/templates are created in Word/Excel startup folders on Windows, suggesting persistence attempts.
sigmaWindowshigh2022-06-02Azure Audit Logs: Application URI Configuration Changes (AppAddress)
Alerts on Azure audit log events indicating an application URI (AppAddress) was modified.
sigmaCloudhigh2022-06-02Azure Audit Logs: Application AppID URI Updates via App or Service Principal Changes
Alerts on Azure audit log entries indicating updates to an application or service principal AppID URI configuration.
sigmaCloudhigh2022-06-02Windows Office Child Process with Directory Traversal Patterns
Alerts on Office parent processes launching child commands containing directory traversal patterns.
sigmahigh2022-06-02Windows sdiagnhost.exe Spawns Suspicious Child Process (PowerShell/CMD/MSHTA/etc.)
Alert when sdiagnhost.exe launches high-risk child processes like PowerShell or CMD, excluding selected benign-like command patterns.
sigmaWindowshigh2022-06-01Windows msdt.exe Execution with Suspicious Parent Process
Alerts when msdt.exe runs under common command-and-script or utility parent processes on Windows.
sigmaWindowshigh2022-06-01Azure Sign-in Logs: Conditional Access Blocked Sign-in Failures (ResultType 53003)
Alerts on Azure sign-ins blocked by Conditional Access when requirements are not met.
sigmaCloudhigh2022-06-01Windows msdt.exe / ms-msdt Handler Arbitrary Command Execution Attempts
Alerts on Windows executions of msdt.exe with command-line indicators suggesting arbitrary command execution.
sigmaWindowshigh2022-05-29Windows Registry: OneDriveStandaloneUpdater.exe URL From UpdateOfficeConfig for Proxy Download
Alerts on registry settings that redirect OneDrive update URL retrieval from UpdateOfficeConfig for internet downloads.
sigmaWindowshigh2022-05-28Windows PowerShell detects obfuscated Net.Webclient casing anomalies in command line
Alerts when PowerShell command lines contain encoded obfuscation patterns referencing Net.Webclient with anomalous casing.
sigmaWindowshigh2022-05-24Windows PowerShell Process Command Lines With Encoded Command Flags
Alerts on PowerShell (pwsh) command lines using encoded command flags and encoded-looking substrings, excluding gc_worker.exe-related activity.
sigmaWindowshigh2022-05-24Windows AnyDesk Executed from Suspicious Directory
Alerts on AnyDesk execution from non-standard folders on Windows, indicating potential remote access abuse.
sigmaWindowshigh2022-05-20