Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Creation: ADCSPwn Command-Line Parameters Indicating ADCS Abuse
Identifies Windows processes with command-line arguments consistent with ADCSPwn targeting ADCS and a specified port.
sigmaWindowshigh2021-07-31Windows Named Pipe Creation: Cobalt Strike Malleable Profile PipeName Patterns
Alerts on Sysmon named pipe creation with PipeName patterns commonly used by Cobalt Strike malleable C2.
sigmaWindowshigh2021-07-30Windows WinDivert Driver Load via Image or Known IMPHASHes
Detects WinDivert-related Windows driver loads using loaded image paths or known IMPHASH values.
sigmaWindowshigh2021-07-30PowerShell SAM Hive Copy via Volume Shadow Copy Paths on Windows
Flags PowerShell commands that copy the SAM hive from Volume Shadow Copy locations using .NET or PowerShell copy semantics.
sigmaWindowshigh2021-07-29Windows Process Creation: Impacket HackTool Binary Execution via Named Image Matches
Flags execution of Windows impacket compiled binaries based on distinctive tool names in the process Image.
sigmaWindowshigh2021-07-24Windows File Writes of HiveNightmare-Style SAM Export Artifacts
Identifies Windows SAM export files written with HiveNightmare-style filename patterns in file events.
sigmaWindowshigh2021-07-23Windows Process Creation: Netcat (ncat/cat) Suspicious Execution
Alerts on Windows process launches of Netcat-like binaries with typical listener/proxy or remote execution command-line flags.
sigmaWindowshigh2021-07-21Windows mshta.exe Process Creation Triggered by Suspicious Command Lines
Alert on mshta.exe launches from suspicious parents and script-like command lines/paths.
sigmaWindowshigh2021-07-17PowerShell executes ADRecon.ps1 AD reconnaissance functions and writes ADRecon-Report.xlsx
Detects PowerShell ADRecon reconnaissance script content by matching AD discovery functions and the default ADRecon report output name.
sigmaWindowshigh2021-07-16Windows: Suspicious Parent-Serv-U.exe Command-Line Process Spawning
Alerts when Serv-U (\Serv-U.exe) spawns typical command interpreters or execution utilities on Windows.
sigmaWindowshigh2021-07-14Windows reg.exe Used to Modify Security Service Start Parameters
Flags reg.exe registry changes that target Start parameters for common security and Windows Defender-related services.
sigmaWindowshigh2021-07-14Windows PowerShell: AtomicTestHarness Invoke-ATHRemoteFXvGPUDisablementCommand Abuse
Alerts on Windows process command lines invoking AtomicTestHarnesses RemoteFXvGPUDisablement PowerShell execution.
sigmaWindowshigh2021-07-13Windows PowerShell Module Creation With RemoteFXvGPUDisablement ModuleContents
Flags PowerShell module creation where ModuleContents includes Get-VMRemoteFXPhysicalVideoAdapter.
sigmaWindowshigh2021-07-13Windows PowerShell ModuleContents Set to Get-VMRemoteFXPhysicalVideoAdapter
Alerts on PowerShell module creation embedding Get-VMRemoteFXPhysicalVideoAdapter, a potential precursor to RemoteFXvGPUDisablement.exe abuse.
sigmaWindowshigh2021-07-13Windows Uninstall CrowdStrike Falcon Sensor via WindowsSensor.exe /uninstall /quiet
Flags Windows processes uninstalling CrowdStrike Falcon Sensor using WindowsSensor.exe with /uninstall and /quiet.
sigmaWindowshigh2021-07-12Windows Process Injection via Mavinject Using INJECTRUNNING Flag
Alerts on Windows process creation using Mavinject with /INJECTRUNNING, indicative of DLL injection into a running process.
sigmaWindowshigh2021-07-12Windows spoolsv.exe Child Process Execution Indicators
Flags suspicious process executions where spoolsv.exe (print spooler) spawns utility, scripting, or rundll32 children with high integrity.
sigmaWindowshigh2021-07-11Windows Process Creation: MpCmdRun.exe Removing All Windows Defender Definitions
Flags MpCmdRun.exe launched to remove all Windows Defender definition files.
sigmaWindowshigh2021-07-07Windows windefend: Detect Tamper Protection blocks changes to Microsoft Defender settings
Flags Defender tamper protection blocks to disable key Microsoft Defender Antivirus and real-time protection settings.
sigmaWindowshigh2021-07-05Windows Suspicious DLL Deletion in Spooler Driver Folder (PrintNightmare/CVE-2021-1675)
Alerts when spoolsv.exe deletes a DLL from the Spooler driver folder path on Windows.
sigmahigh2021-07-01