Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Suspicious UltraVNC Command Line With Auto-Reconnect Flags
Alerts on UltraVNC execution using -autoreconnect with -connect and -id in the Windows command line.
sigmaWindowshigh2022-03-04PowerShell Base64 Encoded MpPreference Command Lines for Windows Defender Modification
Detects PowerShell Base64 command lines referencing Add-MpPreference/Set-MpPreference to modify Microsoft Defender AV settings.
sigmaWindowshigh2022-03-04Windows PowerShell: Disable Microsoft Defender Scanning via Set-MpPreference
Flags PowerShell commands that disable Microsoft Defender scanning/protection settings using Set-MpPreference, including encoded variants.
sigmaWindowshigh2022-03-03Windows Process Creation: Base64-Obfuscated .NET Reflection Assembly Load Call
Alerts on command lines containing Base64-encoded obfuscation for .NET reflection assembly load calls.
sigmaWindowshigh2022-03-01Windows PowerShell: Base64 Encoded Reflective .NET Assembly Load
Flags PowerShell command lines containing Base64 fragments consistent with reflective .NET Assembly.Load usage.
sigmaWindowshigh2022-03-01Windows PowerShell CommandLine downloads and executes via WebClient with IEX or DownloadFile
Alerts on PowerShell command lines that use WebClient downloads combined with IEX or DownloadFile, typical of staged payload execution.
sigmaWindowshigh2022-02-28Windows: Suspicious Process Spawn by Outlook Parent
Alerts on Windows process launches where Outlook.exe spawns known high-risk command execution binaries.
sigmaWindowshigh2022-02-28Suspicious wuauclt.exe Process Creation on Windows with Empty Command-Line Flags
Alert on Windows Update Agent wuauclt.exe launches that have command lines ending with no flags/arguments.
sigmaWindowshigh2022-02-26Windows: Suspicious Parent Process Execution From \Users\Public Spawning Scripting/Shell Binaries
Alerts on processes launched from \Users\Public that execute common scripting/shell binaries or command-line markers.
sigmaWindowshigh2022-02-25Windows process creation: CrackMapExec execution via characteristic command-line flags
Alerts on Windows process creation showing CrackMapExec-style command-line flags for local auth and module execution.
sigmaWindowshigh2022-02-25Windows MSExchangeMailboxReplication .aspx/.asp File Writes Indicating Web Shell Upload
Alerts when MSExchangeMailboxReplication.exe writes .asp or .aspx files on Windows, indicating potentially malicious server-side script drops.
sigmaWindowshigh2022-02-25Windows Process Creation: Hermetic Wiper–style Postgres/PowerShell Command-Line Patterns
Flags Windows process creation with wiper-like PowerShell comsvcs MiniDump and related command-line/paths.
sigmahigh2022-02-25Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Flags Windows process creation command-line patterns consistent with BlackByte ransomware techniques.
sigmahigh2022-02-25Windows Scheduled Task Creation via schtasks with Suspicious Command-Line Patterns
Flags schtasks.exe /Create commands containing suspicious interpreter, encoding, hidden execution, or unusual path/script components.
sigmaWindowshigh2022-02-23Windows explorer.exe spawned with /NOUACCHECK flag for UAC bypass behavior
Alerts on explorer.exe executions that include /NOUACCHECK, indicating potential bypass of UAC checks for child processes.
sigmaWindowshigh2022-02-23Windows Process Execution of Tor or Tor Browser (tor.exe / Firefox-based)
Flags Windows execution of tor.exe or Tor Browser’s bundled Firefox from the expected installation path.
sigmaWindowshigh2022-02-20Windows Sysmon DNS Query to .onion or Tor Gateway Domains
Alerts when Windows Sysmon DNS queries target .onion or Tor gateway/proxy-related domain suffixes.
sigmaWindowshigh2022-02-20Windows DNS Client Query for .onion and Tor-related Domains
Alerts on Windows DNS queries resolving .onion and related Tor/hidden-service domains.
sigmaWindowshigh2022-02-20Windows: Rundll32 Executing Registered COM Local Servers via Command-Line { }
Flags rundll32.exe launching COM local servers using -sta/-localserver with braced arguments.
sigmaWindowshigh2022-02-13Windows schtasks Creates Registry-Backed Base64 PowerShell Payload via Encoded Command
Flags schtasks.exe scheduling that triggers PowerShell to decode a base64 payload pulled from Windows Registry.
sigmaWindowshigh2022-02-12