Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Creation: UAC Bypass via winsat.exe Path Parsing
Alerts on elevated processes spawned by Temp-path winsat.exe with system32 winsat command-line content.
sigmaWindowshigh2021-08-30Windows UAC Bypass via NTFS Reparse Point: wusa.exe DLL Hijacking Process Behavior
Alerts on high-integrity wusa.exe launched from Temp update.msu with a dism.exe parent showing DismHost activity.
sigmaWindowshigh2021-08-30Windows UAC Bypass via msconfig Token Modification (msconfig.exe -5) Process Creation
Flags msconfig.exe invoked with -5 from a Temp pkgmgr.exe parent under elevated integrity levels, indicating a possible UAC bypass.
sigmaWindowshigh2021-08-30Windows UAC Bypass via IEInstal.exe Launching consent.exe from Temp with Elevated Integrity
Alerts on elevated consent.exe spawned by ieinstal.exe from Temp, indicating a possible Windows UAC bypass chain.
sigmaWindowshigh2021-08-30Windows UAC Bypass via DismHost.exe DLL Hijacking
Flags DismHost.exe executions from AppData\Local\Temp running as High/System integrity, consistent with UAC bypass via DLL hijacking.
sigmaWindowshigh2021-08-30Windows UAC Bypass via Disk Cleanup cleanmgr.exe run from Scheduled Task
Flags scheduled-task executions of cleanmgr.exe with disk-cleanup parameters running at high/System integrity.
sigmaWindowshigh2021-08-30Windows: Detect UACMe (Akagi.exe) execution via PE metadata and image name
Flags Windows processes likely running UACMe (Akagi.exe/Akagi64.exe) using PE metadata and known IMPHASH indicators.
sigmaWindowshigh2021-08-30Windows: Detect UAC bypass attempts via winsat.exe path parsing from user temp
Flags file activity targeting Temp\system32\winsat.exe (or winmm.dll) under C:\Users\ consistent with a UAC bypass attempt.
sigmaWindowshigh2021-08-30Windows UAC bypass using NTFS reparse point to place a hijack DLL in Temp
Alerts on file events pointing to a Temp legacy kernel32 DLL within user AppData, consistent with UAC bypass via reparse/DLL targeting.
sigmaWindowshigh2021-08-30Windows UAC Bypass via msconfig Token Modification Dropping pkgmgr.exe from Temp
Alerts on writes to C:\Users\…\AppData\Local\Temp\pkgmgr.exe indicative of msconfig-based UAC bypass staging.
sigmaWindowshigh2021-08-30Windows UAC bypass via IEInstal.exe dropping consent.exe to Temp
Alerts on IEInstal.exe activity writing consent.exe under AppData Local Temp to support a UAC bypass attempt.
sigmaWindowshigh2021-08-30Windows UAC Bypass via .NET Code Profiler DLL Hijacking on mmc.exe (pe386.dll in Temp)
Flags creation of Temp\pe386.dll under a user profile, consistent with mmc/.NET code profiler UAC bypass behavior.
sigmaWindowshigh2021-08-30Exchange Management: Removal of Mailbox Export Request via Remove-MailboxExportRequest
Detects Exchange management removals of mailbox export requests using Remove-MailboxExportRequest with Confirm set to "False".
sigmaWindowshigh2021-08-27Windows Registry UAC Bypass Attempt via Windows Media Player osk.exe AppCompatFlags
Identifies registry AppCompatFlags entries for Windows Media Player osk.exe that may indicate a UAC bypass attempt.
sigmaWindowshigh2021-08-23Windows WmiPrvSE.exe Spawning Suspicious Script and LOLBIN Child Processes
Flags WmiPrvSE.exe spawning script/utility executables like mshta or regsvr32, with command-line keywords where applicable.
sigmaWindowshigh2021-08-23Windows Process Creation: Office-Launched WMIC with LOLBIN-Style Command Arguments
Alerts on Office spawning WMIC.exe with process/create/call arguments and LOLBIN-like tool references.
sigmaWindowshigh2021-08-23Windows UAC bypass using wsreset.exe with high/SYSTEM integrity
Alerts when wsreset.exe is executed with elevated integrity (High or SYSTEM), indicating a potential UAC bypass attempt.
sigmaWindowshigh2021-08-23Windows Process UAC Bypass via Windows Media Player osksupport.dll (osk.exe → cmd.exe)
Alerts on osk.exe spawning cmd.exe under mmc event viewer with high/system integrity, consistent with a UAC bypass attempt.
sigmaWindowshigh2021-08-23Windows UAC Bypass via pkgmgr.exe Launching dism.exe (High/System Integrity)
Detects pkgmgr.exe spawning dism.exe with High/System integrity levels on Windows, a pattern used in UAC bypass attempts.
sigmaWindowshigh2021-08-23Windows UAC Bypass via consent.exe and werfault.exe with comctl32.dll-related behavior
Alerts on consent.exe parent launching werfault.exe with high/system integrity levels, consistent with potential UAC bypass attempts.
sigmaWindowshigh2021-08-23