Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: File creation of C:\program.exe enabling unquoted service path execution
Flags creation of C:\program.exe that can be used to hijack unquoted Windows service binary paths.
sigmaWindowshigh2021-12-30Windows Registry Startup: Chrome VPN Extensions Installed via Extension Registry Keys
Flags Windows Registry updates that register VPN/proxy Chrome extensions via the Chrome Extensions update_url key.
sigmaWindowshigh2021-12-28Windows Process Creation: Suspicious Kernel Dump via dtrace.exe lkd(0) and syscall:::return
Alerts on Windows process executions of dtrace.exe with command lines consistent with kernel dumping (lkd).
sigmaWindowshigh2021-12-28PowerShell ScriptBlock Requests Kerberos Tickets via IdentityModel Token Assembly
Alerts on PowerShell ScriptBlock text that builds Kerberos ticket requests using KerberosRequestorSecurityToken and .GetRequest().
sigmaWindowshigh2021-12-28PowerShell Script Blocks Register Malicious XLL via Office COM Automation on Windows
Detects PowerShell Script Block content that uses COM automation to call .RegisterXLL for an Office XLL add-in.
sigmaWindowshigh2021-12-28Windows Suspicious File Downloads from Outlook/OneNote Attachment Domains via Command-Line
Flags Windows command-line downloads using curl/wget or PowerShell from Outlook/OneNote attachment domains.
sigmaWindowshigh2021-12-27Windows Process Execution of Hashcat.exe for Password Cracking
Alerts on Hashcat.exe launched with cracking-focused flags targeting an offline SAM-derived dataset.
sigmaWindowshigh2021-12-27Windows: Findstr searches GPP cpassword in SYSVOL XML
Alerts when Windows findstr/find searches SYSVOL XML files for GPP cpassword.
sigmaWindowshigh2021-12-27Windows PowerShell Copies a DLL into System32 or SysWOW64
Flags PowerShell Copy-Item targeting Windows\System32 or Windows\SysWOW64 for file placement.
sigmaWindowshigh2021-12-27Windows schtasks.exe /disable Used to Disable Security-Critical Scheduled Tasks
Flags schtasks.exe executions using /disable against security-critical Windows scheduled task paths.
sigmaWindowshigh2021-12-26Java keytool Spawns System Shells or Scripting Utilities on Windows
Alerts when Java keytool.exe spawns command and script execution binaries like cmd.exe or PowerShell on Windows.
sigmaWindowshigh2021-12-22Windows: Detect Computer Account Rename to Non-Standard Name Missing Trailing '$'
Alerts on Windows 4781 computer account renames where the new name lacks the '$' suffix.
sigmahigh2021-12-22Suspicious Windows Process Creation as SYSTEM User with Likely Credential/Defense Evasion Commands
Flags SYSTEM-context process executions on Windows that include suspicious tool names or command-line patterns such as PowerShell/Mimikatz indicators.
sigmaWindowshigh2021-12-20Windows sqlcmd.exe Credential Dump Query Against VeeamBackup dbo
Alerts on sqlcmd.exe running a query targeting the VeeamBackup dbo Credentials table to dump sensitive credentials.
sigmaWindowshigh2021-12-20Windows: Detect sc.exe Service Creation with DACL Modification (sdset DCLCWPDTSD)
Alerts on sc.exe sdset usage with DCLCWPDTSD, suggesting permission changes to hide or impede service removal.
sigmaWindowshigh2021-12-20Windows CleanWipe-Like PUA Execution via System Tool Uninstall Switches
Flags Windows processes launching CleanWipe-like removal tools with uninstall parameters for security impairment investigation.
sigmaWindowshigh2021-12-18Windows Process Command-Line Flags Indicating Auditpol Policy Tampering
Detects auditpol runs with flags that disable key audit categories, indicating potential audit policy tampering for defense impairment.
sigmaWindowshigh2021-12-18Windows: Alert on Java.exe Spawning Suspicious System and Script Binaries
Triggers when java.exe launches a child utility commonly abused for command execution and administration.
sigmaWindowshigh2021-12-17Windows Sysmon Discovery Attempt via Findstr.exe Default Driver Altitude (385201)
Alerts on findstr/find.exe executions containing 385201, consistent with using Sysmon default driver altitude for discovery.
sigmaWindowshigh2021-12-16Windows wbadmin.exe Deletes All Backup Copies (keepVersions:0)
Flags wbadmin.exe executions that delete all backups/system state backups using keepVersions:0.
sigmaWindowshigh2021-12-13