Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Registry Writes for NetWire-Related Keys
Flags newly added Windows registry keys with paths containing \\software\\NetWire, consistent with potential NetWire-related persistence.
sigmahigh2021-10-07Apache HTTP Server Web Path Traversal Attempt via Encoded Traversal Sequences (CVE-2021-41773)
Alerts on Apache requests with encoded traversal strings that return 200/301, consistent with CVE-2021-41773 probing.
sigmahigh2021-10-05Windows Prefetch File Deletion via .pf File Removal
Flags deletion of .pf files in \\Windows\\Prefetch, a possible attempt to remove execution artifacts.
sigmaWindowshigh2021-09-29Windows Process Memory Dump Using RdrLeakDiag.exe (/memdmp|fullmemdmp)
Alerts on Windows executions of rdrleakdiag.exe that request full or targeted memory dumps via /memdmp or /fullmemdmp.
sigmaWindowshigh2021-09-24VMware vCenter Server file upload exploitation attempt for CVE-2021-22005 via POST telemetry endpoint
Identifies POST requests targeting a vCenter telemetry upload endpoint consistent with CVE-2021-22005 exploitation attempts.
sigmahigh2021-09-24PowerShell Live Memory Dump via Get-StorageDiagnosticInfo with -IncludeLiveDump (Windows)
Identifies PowerShell use of Get-StorageDiagnosticInfo with -IncludeLiveDump to trigger a live memory dump on Windows.
sigmaWindowshigh2021-09-21Windows: Xwizard.exe Execution from Non-Default Directory
Alerts when Xwizard.exe starts from an unexpected Windows path, indicating potential misuse or side-loading.
sigmaWindowshigh2021-09-20Detect suspicious AD SelfService web requests targeting report generation and API endpoints
Flags web requests with URL query strings targeting known ADSelfService exploitation paths for CVE-2021-40539.
sigmahigh2021-09-20Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)
Alert on HTTP 200 POST /wsman with no Authorization header and a non-empty body in Zeek logs, consistent with OMIGOD unauthenticated RCE attempts.
sigmahigh2021-09-20PowerShell Add-DnsClientNrptRule Modifies NRPT Namespaces
Flags PowerShell scripts that add DNS Name Resolution Policy Table rules for a specified namespace.
sigmaWindowshigh2021-09-14Linux Commands Clearing or Removing /var/log/syslog
Flags Linux activity that clears, deletes, or redirects /var/log/syslog, a likely attempt to impair logging.
sigmaLinuxhigh2021-09-10Windows Winword.exe Creates INetCache .cab and .inf Files During CVE-2021-40444 Exploitation
Flags winword.exe writing CABs in INetCache or INF files in Temp consistent with CVE-2021-40444 exploitation.
sigmahigh2021-09-10Windows Process Execution of control.exe Spawned by Office Apps Matching CVE-2021-40444 Pattern
Alerts when control.exe is launched from Office apps with suspicious DLL-related command lines, consistent with CVE-2021-40444 exploitation attempts.
sigmahigh2021-09-08Windows Process Creation: Atlassian Confluence Java Spawns Suspicious Utility Child Processes (CVE-2021-26084)
Flags suspicious child processes spawned by Confluence’s Java on Windows, consistent with attempted CVE-2021-26084 exploitation.
sigmahigh2021-09-08Windows Image Load of clfsw32.dll by svchost.exe indicating PRIVATELOG usage
Alert on svchost.exe loading clfsw32.dll, a rarely observed Windows image load pattern consistent with PRIVATELOG.
sigmahigh2021-09-07Windows Kerberos TGT Request with AD CS Certificate Thumbprint Anomalies (EventID 4768)
Identifies unusual certificate-associated Kerberos TGT (4768) requests targeting computer accounts on Windows.
sigmaWindowshigh2021-09-02Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
Detects WMI event consumer encoded payloads containing suspicious execution-related strings on Windows.
sigmaWindowshigh2021-09-01Windows Atera RMM Agent Installation via MsiInstaller Event ID 1033
Flags Windows MSI installs where installer logs indicate an AteraAgent installation (EventID 1033, MsiInstaller).
sigmaWindowshigh2021-09-01Windows UAC Bypass via ComputerDefaults.exe with Elevated Integrity Parent Process
Flags ComputerDefaults.exe runs at high/system integrity when the parent isn’t from typical system or Program Files paths.
sigmaWindowshigh2021-08-31Windows Registry UAC Bypass via winsat.exe LowerCaseLongPath and UACMe Path Parsing
Matches registry writes that reference winsat.exe using a LowerCaseLongPath construction consistent with UAC bypass path parsing.
sigmaWindowshigh2021-08-30