Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows PUA: Suspicious Active Directory enumeration using AdFind.exe flags
Flags AdFind.exe processes that look like Active Directory discovery via password policy and object enumeration options.
sigmaWindowshigh2021-12-13Webserver JNDI-Exploit-Kit Exploitation Indicators via Known Payload Paths
Flags webserver requests whose URL paths match known JNDI-Exploit-Kit exploit, deserialization, and memshell pattern strings.
sigmaWebhigh2021-12-12Windows Process Creation: SharpView.exe with Recon/Domain Discovery Cmdlets
Alerts when SharpView.exe runs with command-line indicators of AD and network discovery/enumeration activity.
sigmaWindowshigh2021-12-10Webserver log detection of Log4j CVE-2021-44228 JNDI payloads in User-Agent, URI query, or Referer
Flags webserver requests with ${jndi:...} payloads in User-Agent, URI query, or Referer indicative of Log4Shell attempts.
sigmahigh2021-12-10Webserver detection of Log4j RCE (CVE-2021-44228) JNDI injection patterns
Detects webserver traffic containing Log4Shell-style JNDI injection payload strings, excluding Nessus scan artifacts.
sigmahigh2021-12-10Windows Process Creation: Executable Image Missing Absolute Path (Possible Process Ghosting)
Flags Windows process creation where the executable Image lacks an absolute path, potentially indicating process ghosting.
sigmaWindowshigh2021-12-09Windows: Suspicious PowerShell Interactive History Files Created as SYSTEM
Alerts on creation of PowerShell interactive history/profile files under SYSTEM, signaling privileged PowerShell activity.
sigmaWindowshigh2021-12-07Windows: User Added to Local Remote Desktop Users Group via Net or PowerShell
Detects Windows command-line activity that adds a user to the local Remote Desktop Users group using net localgroup or Add-LocalGroupMember.
sigmaWindowshigh2021-12-06Windows Process Command Line Containing Whoami as First Parameter
Flags Windows process creations with command lines containing '.exe whoami' to surface potential discovery behavior.
sigmaWindowshigh2021-11-29Windows Regsvr32.exe Executed with Suspicious File Extension Masquerading as DLL
Alerts when REGSVR32.exe runs with a command-line argument ending in a suspicious masquerade file extension.
sigmaWindowshigh2021-11-29Windows File Writes from NPPSpy Hacktool: NPPSpy.txt and NPPSpy.dll
Alerts on Windows file events writing NPPSpy.txt or NPPSpy.dll, consistent with credential dumping by the NPPSpy hacktool.
sigmaWindowshigh2021-11-29Windows Process Creation: Dump64.EXE Renamed into Visual Studio Folder
Alerts on Visual Studio–staged dump64.exe masquerading, potentially indicating an attempt to bypass Windows Defender AV.
sigmaWindowshigh2021-11-26Azure AuditLogs: Privileged role assignment to user access admin
Flags Azure AuditLogs events where a user is assigned to User Access Administrator, enabling full subscription management.
sigmaCloudhigh2021-11-26Azure Activity Logs: Authorization ElevateAccess Grants Subscription-Level Management
Alerts on Azure Activity Log authorization elevation actions that can grant access to manage all subscriptions.
sigmaCloudhigh2021-11-26Windows PowerShell Clears Console History via Clear-History
Flags PowerShell attempts to clear or delete console/PSReadline command history to hinder command forensics.
sigmaWindowshigh2021-11-25Windows: Rundll32 Loading shell32.dll via Control_RunDLL from User/Temp Paths
Alerts on rundll32.exe loading shell32.dll with Control_RunDLL from AppData/Temp/user paths.
sigmaWindowshigh2021-11-24Windows CertReq -Post Download Attempt via HTTP
Flags certreq.exe executions using -Post -config and HTTP content retrieval indicators.
sigmaWindowshigh2021-11-24Windows PsExec/PAExec Command-Line Flags Escalating to LOCAL SYSTEM
Flags in PsExec/PAExec command lines requesting LOCAL SYSTEM execution are matched via process creation command-line telemetry.
sigmaWindowshigh2021-11-23Windows MSIInstaller EventID 1033 PoC File Takeover String Match (InstallerFileTakeOver/CVE-2021-41379)
Alert on Windows MSI installer EventID 1033 with event data containing 'test pkg', consistent with PoC activity for CVE-2021-41379.
sigmahigh2021-11-22Windows Shell/Scripting Tool File Write to Suspicious Directories
Alert on file writes by common Windows shells/scripting tools to C:\PerfLogs, C:\Users\Public, or C:\Windows\Temp.
sigmaWindowshigh2021-11-20