Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows PowerShell execution from C:\Users\Public
Flags PowerShell command lines that reference C:\Users\Public, indicating likely script execution from a common public staging area.
sigmaWindowshigh2022-04-06Windows: Detect Suspicious DumpMinitool.exe Execution via Process Command-Line
Alerts on suspicious command-line usage of DumpMinitool.exe on Windows, leveraging process creation Image, OriginalFileName, and command-line text.
sigmaWindowshigh2022-04-06Windows Registry Key Change Disabling System Restore
Detects registry writes that disable Windows System Restore via policy/config keys set to DWORD 0x00000001.
sigmaWindowshigh2022-04-04Windows Registry Service Persistence via SafeBoot Control Keys
Flags Windows registry writes that configure a service to load in Safe Mode (SafeBoot Minimal/Network).
sigmaWindowshigh2022-04-04Windows Registry Key Changes Disabling PowerShell Logging for Current User
Detects registry changes that disable PowerShell module/script logging and transcription by setting logging keys to DWORD 0.
sigmaWindowshigh2022-04-02Windows PowerShell IEX Invocation Patterns in Process Creation Command Lines
Alerts on suspicious PowerShell command lines that pipe or otherwise invoke IEX and may include Base64 decoding.
sigmaWindowshigh2022-03-24Windows PowerShell Download and Execution Cradles
Flags PowerShell commands that download remote content and immediately execute it using IEX/Invoke-Expression.
sigmaWindowshigh2022-03-24Windows: reg.exe Registry Tampering of Windows Defender Policy Keys
Detects reg.exe adding Defender DWORD policy values to disable or suppress multiple protection features via Windows registry.
sigmaWindowshigh2022-03-22Windows Suspicious Parent Processes: Unusual Child Creation by System Utilities
Alerts when predefined suspicious Windows parent executables spawn unusual or unrecognized child processes.
sigmaWindowshigh2022-03-21Windows Service Control Manager: HackTool Service Installation or Start via Suspicious Service Names
Detects Windows service creation/start events tied to hacktool-like service names or ImagePath indicators.
sigmaWindowshigh2022-03-21Windows Scheduled Task Backdoor Execution via cmd.exe or PowerShell (System EventID /create /delete)
Flags cmd.exe/powershell.exe command lines that create a System/EventID-based scheduled task to run a payload.
sigmahigh2022-03-21Windows Service Installation via Scripted ImagePath Indicators (Event 7045)
Identifies suspicious Windows service installations that embed script host execution via Event ID 7045 ImagePath patterns.
sigmaWindowshigh2022-03-18Windows Service Installation with Suspicious ProgramData/Root Executable Image Paths
Flags Windows service installs (Event 7045) that reference suspicious EXE paths in ProgramData or directly under C:\.
sigmaWindowshigh2022-03-18Windows Service Installation with PowerShell Download and Hidden Execution
Alerts on Windows service creation (7045) with ImagePath patterns indicating hidden/staged command execution.
sigmaWindowshigh2022-03-18Windows Webserver Parent Process Launching Credential Dumping and Exfiltration Commands
Flags web server processes spawning child commands consistent with credential dumping, exfiltration, and privilege changes.
sigmaWindowshigh2022-03-17Windows PowerShell: Suspicious Get-ADDBAccount access to ntds.dit via BootKey and DatabasePath
Alerts on PowerShell invocations of Get-ADDBAccount that reference BootKey and DatabasePath for ntds.dit credential access.
sigmaWindowshigh2022-03-16Windows schtasks.exe Create Executes File from AppData\Local
Alerts on schtasks.exe creating tasks that run payloads from C:\Users\<user>\AppData\Local.
sigmaWindowshigh2022-03-15Windows HackTool Process Patterns for CrackMapExec LSASS Dumping
Alerts on Windows command-line process patterns consistent with LSASS dumping in CrackMapExec workflows.
sigmaWindowshigh2022-03-12Windows Process Creation: Detect NTDS.DIT and Registry Hive Exfiltration Tooling
Detects suspicious Windows processes that reference NTDS.DIT/SYSTEM hive dumping or staging via common NTDS tooling and scripts.
sigmaWindowshigh2022-03-11Windows NTDS Exfiltration File Creation by NTDS Export Filename Patterns
Alerts on Windows file creates using common NTDS-DIT dump/exfiltration filename suffixes like \All.cab and .ntds.cleartext.
sigmaWindowshigh2022-03-11