Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Creation: Explorer Command Lines with Unicode Whitespace Padding and '#'
Alerts when Explorer spawns a process with command lines containing long Unicode whitespace padding followed by '#'.
sigmaWindowshigh2025-11-04Windows Application Logs: Detect WSUS deserialization exploitation via InvalidCastException indicators
Flags WSUS (EventID 7053) application log errors matching invalid cast/object data provider strings indicative of CVE-2025-59287 exploitation.
sigmahigh2025-10-31Windows Process Creation: Suspicious cmd.exe or PowerShell Child of WSUS (wsusservice.exe)
Alerts when WSUS/IIS service processes spawn cmd or PowerShell interpreters, indicating potential exploitation and post-exploitation activity.
sigmahigh2025-10-31Windows SpeechRuntime.exe Child Process Creation
Alerts when SpeechRuntime.exe spawns a child process, highlighting potential abuse for lateral movement on Windows.
sigmaWindowshigh2025-10-23Windows Winrs.exe Local Command Execution via localhost/loopback
Alerts on Winrs.exe processes running locally by targeting localhost/loopback in /r or /remote.
sigmaWindowshigh2025-10-22Windows Process Creation: Commvault qlogin Argument Injection Indicators for Auth Bypass
Alerts on Windows command lines running Commvault qlogin with -localadmin-related markers consistent with argument injection.
sigmahigh2025-10-20Windows Process: Commvault qoperation.exe JSP Webroot Path Traversal Webshell Drop
Alerts on qoperation.exe commands that use -file to write a .jsp into a webroot path, consistent with a webshell drop.
sigmahigh2025-10-20AWS CloudTrail Detects EC2 DeleteFlowLogs API Calls
Flags successful EC2 DeleteFlowLogs API calls in CloudTrail indicating VPC Flow Logs were removed.
sigmaCloudhigh2025-10-19Windows: Detect baaupdate.exe Spawning Scripting, Admin, or LOLBin Child Processes
Alerts when baaupdate.exe runs typical script/utility processes, an uncommon parent-child execution pattern on Windows.
sigmaWindowshigh2025-10-18Windows: Detect Suspicious DLL Loads by BaaUpdate.exe from Publicly Writable Paths
Alerts when BaaUpdate.exe loads DLLs from Temp/Public-type locations associated with DLL search hijacking risk.
sigmaWindowshigh2025-10-18Kaspersky Endpoint Security Service Stopped via Command Line on Linux
Flags Linux commands using systemctl/bash/sh to stop Kaspersky (kesl) services, suggesting defense impairment or manual service shutdown.
sigmaLinuxhigh2025-10-18AWS KMS Imported Key Material Import or Deletion via CloudTrail
Detects AWS KMS imported key material events in CloudTrail, including import and deletion of imported key material.
sigmaCloudhigh2025-10-18Windows Process Execution: Restic Backup Tool Command-Line Indicators
Flags Windows executions where Restic is run with repo init/backup flags or remote storage targets.
sigmaWindowshigh2025-10-17Linux systemctl Mask Power Targets to Disable Suspend, Hibernate, Hybrid Sleep
Flags systemctl mask commands targeting suspend/hibernate/hybrid-sleep power management targets.
sigmaLinuxhigh2025-10-17Linux auditctl -D used to delete all audit rules
Flags auditctl -D executions that delete all audit rules and watchers on Linux.
sigmaLinuxhigh2025-10-17WSL Process Execution of Kali Linux on Windows
Flags Kali Linux running under WSL on Windows using process creation image and command-line indicators.
sigmaWindowshigh2025-10-10Windows WSL Kali Linux installation via wsl.exe --install -i
Flags wsl.exe commands that install a distribution specified as Kali Linux using --install -i.
sigmaWindowshigh2025-10-10Windows Process Creation: GoAnywhere child command execution indicating possible MFT exploitation
Flags Windows process trees where GoAnywhere Tomcat spawns suspicious cmd/PowerShell command lines consistent with exploitation activity.
sigmahigh2025-10-07Linux File Creation of /etc/nsswitch.conf in Non-Standard Paths
Flags creation of /etc/nsswitch.conf in non-standard locations that could support privilege escalation.
sigmahigh2025-10-02Windows Registry RunMRU Key Deletion
Alerts on deletion of the Windows Run dialog command history (RunMRU) registry key.
sigmaWindowshigh2025-09-25