Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Suspicious colorcpl.exe file creation/copy to System32 spool drivers color
Alerts on colorcpl.exe creating files in C:\Windows\System32\spool\drivers\color\ with suspicious target filenames.
sigmaWindowshigh2022-01-21Windows: AdvancedRun executed with RunAs IDs under high-privilege service accounts
Detects AdvancedRun execution where /RunAs is set to specific high-privilege IDs in the process command line.
sigmaWindowshigh2022-01-20PowerShell ScriptBlock Logging: Set-MpPreference disables Windows Defender scanning or allows threats
Alert on PowerShell Set-MpPreference usage that disables Defender scanning/monitoring or sets threat default actions to Allow.
sigmaWindowshigh2022-01-16Windows Process Creation: VMware Horizon Log4j RCE Attempt via ws_TomcatService to cmd/powershell
Alert on ws_TomcatService.exe spawning cmd.exe or PowerShell on Windows as suspicious exploitation activity.
sigmahigh2022-01-14Windows: Process creation event for Sysmon uninstall using Sysmon -u
Flags attempts to uninstall Sysmon on Windows by running Sysmon with the -u flag.
sigmaWindowshigh2022-01-12PowerShell Script Creates Volume Shadow Copy via Win32_ShadowCopy
Alerts when PowerShell script blocks invoke Win32_ShadowCopy.Create to create a ClientAccessible shadow copy.
sigmaWindowshigh2022-01-12Windows ProcDump renamed, copied or moved for stealth evasion
Alerts on ProcDump commands that copy/move or rename dump outputs, including LSASS dump filename patterns.
sigmaWindowshigh2022-01-11Windows regsvr32 Downloads Remote DLLs via HTTP/HTTPS IP in /i Parameter
Alerts when regsvr32 is invoked with an /i: HTTP/HTTPS IP pattern to fetch remote DLLs.
sigmaWindowshigh2022-01-11Windows mpiexec.exe LOLBin: Flag combination with -n/n 1 for potential arbitrary execution
Alerts on Windows executions of mpiexec.exe with /n 1 or -n 1, correlated to a specific imphash, indicating LOLBin-style behavior.
sigmaWindowshigh2022-01-11Windows File Events: NTDS.DIT Created by Suspicious or Rare Process
Alerts on creation of ntds.dit on Windows when the creator process image/path is uncommon or located in suspicious directories.
sigmaWindowshigh2022-01-11Windows WScript/CScript File Write With Script Extensions to Temp or Startup Paths
Alerts when WScript/CScript writes script files (.js/.vbs/.wsf/.wsh, etc.) into common temp or Startup directories.
sigmaWindowshigh2022-01-10Windows ChromeLoader Execution via Scheduled Task and Hidden PowerShell Launch
Flags PowerShell-launched chrome.exe that uses --load-extension from local AppData Chrome paths for ChromeLoader-style execution.
sigmahigh2022-01-10Windows: AppCmd disables IIS HTTP logging via dontLog=true
Flags appcmd.exe commands that disable IIS HTTP logging by setting httplogging to dontLog:true.
sigmaWindowshigh2022-01-09PowerShell DNSExfiltrator command usage (DNSExfiltration)
Detects PowerShell use of Invoke-DNSExfiltrator for DNS/DoH-based exfiltration based on Script Block Logging content.
sigmaWindowshigh2022-01-07Windows Registry: Detect windir Environment Key Changes for SilentCleanup UAC Bypass
Detects non-default Environment\windir registry changes commonly used to facilitate SilentCleanup UAC bypass.
sigmaWindowshigh2022-01-06Registry Modification for UAC Bypass via Event Viewer Command Handler (Windows)
Monitors registry value changes to the Event Viewer command handler path indicative of a UAC bypass attempt on Windows.
sigmaWindowshigh2022-01-05Windows Registry: Detect DelegateExecute UAC bypass via TargetObject path
Alerts on registry set events targeting \open\command\DelegateExecute with empty Details, consistent with a UAC bypass attempt.
sigmaWindowshigh2022-01-05Windows Process Creation: Pypykatz Credential Dumping via Registry Parsing
Alerts when pypykatz is run with "live" and "registry" parameters to extract credential data from local SAM-related artifacts.
sigmaWindowshigh2022-01-05Windows: Uncommon format.com File System Load via /fs parameter
Alerts on format.com executions with atypical /fs: parameters, which may indicate defense-evasion use of Windows utilities.
sigmaWindowshigh2022-01-04Windows Process Creation: createdump.exe Dumping Memory with Full and Name Flags
Flags and .dmp output usage indicate createdump.exe dumping process memory on Windows.
sigmaWindowshigh2022-01-04