Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Alerts on Windows 7045 service installs with ImagePath patterns consistent with Cobalt Strike-style PowerShell and execution.
sigmaWindowscritical2021-05-26Windows Named Pipe Creation Matching Cobalt Strike Default Pipe Prefixes
Flags Windows named pipe creation where PipeName matches known Cobalt Strike default pipe prefixes.
sigmaWindowscritical2021-05-25Windows process creation patterns associated with DarkSide ransomware helpers
Detects Windows process creation consistent with DarkSide ransomware helper execution using encoded command-line content.
sigmacritical2021-05-14Webserver Indicators of Successful Exchange CVE-2021-28480 Exploitation via OWA Calendar POST
Flags POST requests to OWA calendar endpoint patterns linked to CVE-2021-28480, excluding HTTP 503 responses.
sigmacritical2021-05-14Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)
Alerts on creation of the "ZzNetSvc" service by Service Control Manager (Event ID 7045) on Windows.
sigmaWindowscritical2021-05-06Windows Driver File MoriyaStreamWatchmen.sys Created in System32\drivers
Alerts when the Windows system32 drivers directory receives the MoriyaStreamWatchmen.sys file.
sigmacritical2021-05-06Windows Process Creation: Exchange Server Artifact Discovery and File Staging Patterns
Alerts on Exchange-focused suspicious Windows command-line activity involving dumping, temp file creation, and compression utilities.
sigmacritical2021-03-09Windows Registry: SilentProcessExit lsass.exe Monitor Registration for Credential Dumping
Alerts on registry registrations for SilentProcessExit monitoring of lsass.exe, a potential precursor to credential dumping.
sigmaWindowscritical2021-02-26Web server requests targeting WebLogic JNDI LDAP via JndiBindingHandle (CVE-2021-2109)
Alerts on GET requests with WebLogic JndiBindingHandle and an ldap:// payload targeting AdminServer.
sigmacritical2021-01-20Windows PowerShell Command Lines with WMI Process Creation and rundll32 Invocation
Flags Windows command lines where PowerShell/WMI is used to spawn rundll32 from c:\windows.
sigmacritical2021-01-20SolarWinds Orion Web API auth bypass probing via suspicious WebResource requests
Detects likely SolarWinds Orion API authentication bypass probing by matching suspicious WebResource/i18n endpoint query strings while filtering known valid requests.
sigmacritical2020-12-27Windows rundll32.exe Command-Line RunDLL or Control_RunDLL Execution
Alerts on rundll32.exe process launches whose command lines end with RunDLL/Control_RunDLL, indicative of DLL function loading.
sigmacritical2020-12-25Windows Process Creation Alerts for Suspicious Lazarus-Linked Command-Line Execution
Alerts on Windows process executions with command-line substrings consistent with behaviors described in Lazarus activity reports.
sigmacritical2020-12-23Detect SolarWinds SUPERNOVA Webshell URL Access on Webservers (logoimagehandler.ashx)
Identifies webserver traffic consistent with SUPERNOVA webshell access targeting logoimagehandler.ashx with a clazz query parameter.
sigmacritical2020-12-17Fortinet SSL VPN Exploitation Attempt via Path Traversal in Web Requests (CVE-2018-13379)
Alerts on HTTP requests matching a Fortinet SSL VPN traversal-style query indicative of CVE-2018-13379 exploitation.
sigmacritical2020-12-08LockerGoga Ransomware Indicators in Windows Process Command Line
Flags Windows processes with a specific LockerGoga-style command-line argument pattern.
sigmacritical2020-10-18Windows Zerologon Exploitation Attempts via Mimikatz or Tools from Kali Host
Identifies Windows Zerologon exploitation attempts tied to Kali-hosted activity and mimikatz-related keywords.
sigmaWindowscritical2020-10-13Windows DCOM InternetExplorer.Application DLL Hijack via iertutil.dll Image Load
Alerts when iexplore.exe loads iertutil.dll from an Internet Explorer path, indicating possible DLL hijacking.
sigmaWindowscritical2020-10-12Windows WMI DLL Hijack via Network-placed wbemcomn.dll in System32\wbem
Alerts when System creates wbemcomn.dll in C:\Windows\System32\wbem\, consistent with WMI DLL hijack file staging.
sigmaWindowscritical2020-10-12Windows DCOM InternetExplorer.Application iertutil.dll DLL Hijack Suspicion
Alerts when System writes iertutil.dll in the DCOM InternetExplorer.Application path, consistent with potential DLL hijacking.
sigmaWindowscritical2020-10-12