Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
117 rules
Linux process discovery via grep/egrep searching for security software strings
Alerts when grep/egrep on Linux searches command lines for indicators of security/monitoring tools.
sigmaLinuxlow2020-10-19Linux Process Discovery: find, ls -R, tree, findmnt, and locate executed
Alerts on Linux execution of file/directory discovery utilities like find, tree, findmnt, recursive ls, and mlocate.
sigmaLinuxinformational2020-10-19Windows Process: reg.exe Software Version Discovery via svcVersion Query
Alerts when reg.exe is used to query \Software\ for svcVersion, indicating Windows software version discovery.
sigmaWindowsmedium2020-10-16Linux Local Groups Discovery via /groups or /etc/group File Enumeration
Detects Linux commands and utilities used to enumerate local groups and read /etc/group.
sigmaLinuxlow2020-10-11Linux System Information Discovery via Common Command-Line Utilities
Flags Linux executions of uname, hostname, uptime, lspci, dmidecode, lscpu, and lsmod for system discovery behavior.
sigmaLinuxinformational2020-10-08Linux System & Hardware Information Discovery via File and Version Reads
Detects Linux file access to BIOS/DMI, hardware model, kernel, and OS release/issue identifiers used for system profiling.
sigmaLinuxinformational2020-10-08Linux Password Policy Discovery via chage and passwd Commands
Identifies Linux password policy discovery by running chage/waswo with status arguments and reading common password policy files.
sigmaLinuxlow2020-10-08Windows Registry Key Export via regedit.exe (-E) to File
Flags regedit.exe registry exports to files using the -E option, indicating potential discovery or exfiltration prep.
sigmaWindowslow2020-10-07macOS Local Network Configuration Discovery via ARP/ifconfig/netstat/networksetup/defaults
Finds macOS network discovery activity by spotting arp/ifconfig/netstat/networksetup/socketfilterfw and specific firewall preference reads.
sigmamacOSinformational2020-10-06Linux System Network Discovery via Firewall/Network Tools
Alerts on Linux process activity running common network/firewall tools and DNS discovery indicators.
sigmaLinuxinformational2020-10-06Linux process discovery via common process listing and monitoring tools
Flags Linux execution of common tools used to enumerate running processes.
sigmalow2020-10-06Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Alerts on SharpHound/Bloodhound-like processes launching with discovery-focused command-line parameters.
sigmaWindowshigh2019-12-20Windows System Time Discovery via net.exe or w32tm.exe
Flags Windows net.exe/net1.exe or w32tm.exe command lines used to query system time/time zone.
sigmaWindowslow2019-10-24Windows Domain Trust Discovery Using dsquery.exe TrustedDomain Queries
Flags Windows executions of dsquery.exe with trustedDomain to discover Active Directory domain trusts.
sigmaWindowsmedium2019-10-24Windows Local Account Discovery via System Utilities Process Execution
Flags Windows processes that match utilities used to enumerate local user and account information.
sigmaWindowslow2019-10-21Linux System Owner or User Discovery via Common Utility Execution
Flags execution of Linux user/system identification utilities such as whoami and id.
sigmaLinuxlow2019-10-21Cisco AAA discovery via show/dir commands
Alerts on Cisco AAA log entries with discovery-oriented 'dir' and 'show' command keywords.
sigmaNetworklow2019-08-12