Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows UAC bypass via changepk.exe launched from slui.exe with elevated integrity
Flags changepk.exe execution from slui.exe with High/System integrity to identify potential UAC bypass behavior on Windows.
sigmaWindowshigh2021-08-23Windows Process Creation: Suspicious splwow64.exe Missing Command-Line Parameters
Flags Windows executions of splwow64.exe where the command line ends at the executable with no parameters.
sigmaWindowshigh2021-08-23Windows UAC Bypass via WoW64 Logger DLL Hijack (Process Access Pattern)
Flags SysWOW64 process-access behavior with high granted access and unknown call traces consistent with a WoW64 logger DLL hijack UAC bypass.
sigmaWindowshigh2021-08-23Windows Named Pipe Creation Matching EfsPotato-Style \\pipe\\srvsvc
Alerts on Windows named pipe creation events matching an EfsPotato-style PipeName pattern (\pipe\ and \pipe\srvsvc), excluding common benign contexts.
sigmaWindowshigh2021-08-23UAC Bypass via Windows Media Player: DllHost.exe spawning osk.exe writing OskSupport.dll to Temp
Flags file events where Temp\OskSupport.dll is targeted alongside DllHost.exe and Windows Media Player\osk.exe, consistent with a UAC bypass attempt.
sigmaWindowshigh2021-08-23Windows UAC Bypass via consent.exe with comctl32.dll file path pattern
Detects suspicious target path patterns involving consent.exe.@ and comctl32.dll consistent with UAC bypass staging.
sigmaWindowshigh2021-08-23Windows Office Applications Creating Executable/Script Files with Suspicious Extensions
Flags Office application processes creating .exe/.dll/.ps1 and other script or executable files on Windows.
sigmaWindowshigh2021-08-23Windows: Suspicious explorer.exe Child Process Spawned by RazerInstaller.exe
Flags explorer.exe spawned by RazerInstaller.exe when the installer runs at System/high integrity.
sigmahigh2021-08-23PowerShell Write-Hijack HackTool Creates .bat for DLL Hijack Execution (Windows)
Flags PowerShell creating .bat files consistent with PowerUp Write-Hijack DLL abuse on Windows.
sigmaWindowshigh2021-08-21Antivirus alerts on known hacktool and attack tool signatures
Alerts on Antivirus detections matching hacktool signature prefixes or offensive tool names for investigation.
sigmahigh2021-08-16Windows: SQLCmd used to dump database metadata and backups
Alerts on Windows executions of sqlcmd.exe with local server targeting and database enumeration/backup query fragments.
sigmahigh2021-08-16Webserver GET requests containing XSS-related payload strings
Finds likely XSS injection attempts in webserver GET requests by matching script, tag, and JS payload strings while excluding 404s.
sigmaWebhigh2021-08-15Windows Maldoc Process Injection via winword.exe CallTrace from LittleCorporal
Flags winword.exe process injection where the call trace matches LittleCorporal-generated Maldoc activity on Windows.
sigmaWindowshigh2021-08-09PowerShell ShellIntel Commandlet Abuse via ScriptBlock Logging
Flags PowerShell script blocks that reference known ShellIntel commandlets tied to exploitation activity.
sigmaWindowshigh2021-08-09AWS CloudTrail UpdateLoginProfile: Password/Authentication Profile Modified for Another User
Flags AWS IAM UpdateLoginProfile events where an account updates another user’s login profile password.
sigmaCloudhigh2021-08-09Windows Process Creation: Detects Volume Shadow Copy Listing via vssadmin
Alerts on Windows command lines that list VSS shadow copies and write results to log.txt.
sigmahigh2021-08-09Detects ProxyShell-Style Exchange Probing via /autodiscover.json and PowerShell URIs (HTTP 401)
Flags Exchange web requests with ProxyShell-like /autodiscover.json query patterns and PowerShell/EWS-related parameters, often returning HTTP 401.
sigmahigh2021-08-07Windows AnyDesk Silent Installation via Command-Line Flags
Identifies AnyDesk being silently installed on Windows using --install, --start-with-win, and --silent command-line flags.
sigmaWindowshigh2021-08-06Windows Registry: Disabling Windows Defender PUA Protection via PUAProtection DWORD
Flags registry changes that set Windows Defender PUAProtection DWORD to 0x00000000 to disable PUA protection.
sigmaWindowshigh2021-08-04Windows process access matching Cobalt Strike BOF injection call trace
Flags suspicious Windows process access consistent with CobaltStrike BOF injection using ntdll/KERNELBASE call traces and high GrantedAccess.
sigmaWindowshigh2021-08-04