Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Registry New File Association via exefile Handler (Classes\*.exefile)
Alerts on Windows registry changes creating a new file association that points to the exefile handler.
sigmaWindowshigh2021-11-19Windows MSExchange Management events indicating likely MS Exchange RCE CVE-2021-42321 exploitation
Flags Exchange management events showing Get-App cmdlet failures and unhandled InvalidCastException during CVE-2021-42321 RCE attempts.
sigmahigh2021-11-18Windows ADCS Template Enrollment Supplies Subject and Risky EKU (Event ID 4898/4899)
Flags ADCS template load/update events (4898/4899) when risky EKU OIDs and enrollee-supplied subject are present.
sigmaWindowshigh2021-11-17Sitecore Pre-Auth RCE (CVE-2021-42237) exploitation attempts via Report.ashx POST
Alerts on successful HTTP POST traffic targeting Sitecore Reporting Report.ashx associated with CVE-2021-42237.
sigmahigh2021-11-17Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Alerts on scheduled task storage writes under System32\Tasks originating from suspicious process locations.
sigmaWindowshigh2021-11-16Windows: reg.exe Adds BitLocker Policy Registry Values
Flags reg.exe registry additions targeting BitLocker policy keys associated with configuration changes.
sigmaWindowshigh2021-11-15Windows LSASS Memory Dump File Creation
Alerts on Windows file creation of LSASS memory dump artifacts identified by high-confidence filename patterns.
sigmaWindowshigh2021-11-15Linux: Kernel Module Loading via insmod (kmod)
Flags Linux auditd syscalls where insmod is executed via /usr/bin/kmod to load a kernel module.
sigmaLinuxhigh2021-11-02Windows Process Creation: Command-Line Indicators of Crypto Mining
Alerts on Windows processes with command-line arguments matching common crypto miner pool and configuration indicators.
sigmaWindowshigh2021-10-26Windows Network Connections to Known Crypto Mining Pools
Flags Windows hosts making outbound connections to known cryptocurrency mining pool domains.
sigmaWindowshigh2021-10-26Linux Process Creation Crypto Miner Command-Line Indicators
Alerts on Linux process executions with command-line strings typical of crypto mining pools, stratum endpoints, and miner options.
sigmaLinuxhigh2021-10-26Linux Process Network Connections to Crypto Mining Pool Hosts
Flags Linux outbound connections to known Monero mining pool domains.
sigmaLinuxhigh2021-10-26PowerShell Creating Startup .lnk Shortcut Persistence (Windows File Events)
Detects PowerShell writing .lnk files into the Windows Startup folder, a common persistence mechanism.
sigmaWindowshigh2021-10-24DNS Queries for Monero Mining Pool Domains
Alerts on DNS queries to known Monero mining pool domains that may indicate cryptomining activity.
sigmaNetworkhigh2021-10-24Windows Process Execution via WorkFolders.exe Launching control.exe
Alerts when WorkFolders.exe spawns a non-standard control.exe instance on Windows.
sigmaWindowshigh2021-10-21Windows process execution via stordiag.exe launching schtasks.exe, systeminfo.exe, or fltmc.exe
Detects stordiag.exe spawning schtasks.exe, systeminfo.exe, or fltmc.exe to support system discovery or config actions on Windows.
sigmaWindowshigh2021-10-21Windows Registry: Clearing RDP Client Connection History via MRU and Server Keys Deletion
Flags registry deletions that remove Windows RDP client connection history from Terminal Server Client MRU and Servers keys.
sigmaWindowshigh2021-10-19Linux Process Creation Webshell Tooling: Web Server Child Processes Running System Commands
Detects web server processes spawning Linux command-line tools commonly used for host discovery or persistence.
sigmaLinuxhigh2021-10-15Linux Syslog Clearing or Removal Using System Utilities
Alert on Linux commands that clear, delete, truncate, or redirect /var/log/syslog or rotate/vacuum journald logs.
sigmaLinuxhigh2021-10-15Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
sigmaWindowshigh2021-10-08