Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Detect ngrok Traffic Forwarded to Local RDP Port via TerminalServices Logs
Detects suspicious ngrok usage that forwards to the local RDP port using Windows TerminalServices-LocalSessionManager EventID 21.
sigmaWindowshigh2022-04-29Windows: rundll32.exe spawning explorer.exe child process (shell32.Control_RunDLL)
Alerts on rundll32.exe spawning explorer.exe, an uncommon child process pattern that may indicate stealthy execution via shell components.
sigmaWindowshigh2022-04-27Windows Process Creation: KrbRelay.exe Kerberos Relay Tool Execution
Flags Windows process creation for KrbRelay.exe with Kerberos relaying-related command-line arguments.
sigmaWindowshigh2022-04-27Windows Hacktool Execution via PE Metadata Company Field
Flags execution of Windows binaries with PE Company metadata set to "Cube0x0", even when renamed.
sigmaWindowshigh2022-04-27Windows UAC Bypass via Event Viewer RecentViews File Creation
Alerts on suspicious file events to Event Viewer RecentViews paths that may indicate a Windows UAC bypass attempt.
sigmaWindowshigh2022-04-27Windows Successful Local Kerberos Logon to Built-in Administrator (Possible Privilege Escalation)
Alert on successful local (127.0.0.1) Kerberos logons targeting the built-in Administrator SID for potential privilege escalation.
sigmaWindowshigh2022-04-27Windows: Detect KrbRelayUp.exe HackTool Process Execution
Flags Windows process executions of KrbRelayUp.exe with relay/domain and SCM spawn command-line patterns.
sigmaWindowshigh2022-04-26Windows Sysmon Application Popup Crash (Event ID 26)
Flags Application Popup events reporting sysmon64.exe/sysmon.exe “Application Error” (Event ID 26).
sigmaWindowshigh2022-04-26Windows: File Creation of Get-Variable.exe in PowerShell WindowsApps Path
Alerts on creation of Get-Variable.exe in Local\Microsoft\WindowsApps, a potential cmdlet-path hijack.
sigmaWindowshigh2022-04-23Windows Remote Thread Created in KeePass.exe
Flags remote thread creation targeting KeePass.exe, a possible indicator of credential theft.
sigmaWindowshigh2022-04-22Windows: Emotet .LNK Loader Execution via cmd.exe or PowerShell
Alerts on cmd/powershell-launched commands referencing findstr, a .vbs script, and a .lnk file—indicative of shortcut-triggered loader activity.
sigmahigh2022-04-22Windows Rundll32 Key Manager Launch (keymgr KRShowKeyMgr) Credential Access
Alerts on rundll32 launching the Windows Key Manager (keymgr / KRShowKeyMgr), a potential credential access step.
sigmaWindowshigh2022-04-21Windows process contacting Dropbox API from non-Dropbox executables
Alerts when a non-Dropbox executable makes initiated connections to Dropbox API endpoints on Windows.
sigmaWindowshigh2022-04-20Windows Process Execution via 7zFM.exe Indicative of CVE-2022-29072 Exploitation
Alerts when 7zFM.exe spawns cmd.exe or PowerShell with command-line patterns consistent with CVE-2022-29072 exploitation attempts.
sigmahigh2022-04-17Windows schtasks.exe scheduled task creation from suspicious folders
Alerts on schtasks.exe /create using PowerShell/cmd and suspicious folder paths like ProgramData.
sigmaWindowshigh2022-04-15Windows Network Connections Initiated by Eqnedt32.EXE
Identifies outbound network connections started by eqnedt32.exe on Windows.
sigmaWindowshigh2022-04-14Windows RPCSS svchost (-k RPCSS) Process Spawn Anomaly (Potential CVE-2022-26809)
Alerts on svchost.exe running RPCSS spawning anomalous child processes indicative of potential RPC abuse.
sigmahigh2022-04-13Windows File Creation: PowerShell webAdministration Module Path Used in CVE-2022-24527 LPE
Flags Windows file events creating webAdministration.psm1 under PowerShell modules, consistent with CVE-2022-24527 LPE behavior.
sigmahigh2022-04-13Windows Process Creation: SQLite Access to Firefox Profile Databases
Alerts when Windows runs SQLite tooling to query Firefox profile DBs like cookies.sqlite or places.sqlite.
sigmaWindowshigh2022-04-08Windows Task Scheduler persistence using svchost-launched PowerShell with hidden/Bypass flags
Alerts on svchost.exe Schedule tasks spawning PowerShell with hidden window and execution policy bypass flags.
sigmaWindowshigh2022-04-08