Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
Windows PowerShell: Detect Suspicious Opsec Artifacts in Script Module Content
Identifies PowerShell module content containing frequent offensive payload string markers associated with poor operational security.
sigmaWindowscritical2020-10-09Windows Process Creation: Winnti Pipemon setup* Command-Line Parameters
Alerts on Windows processes launching Pipemon-style setup.exe command lines with specific -p or -x:n flags.
sigmacritical2020-07-30Windows DNS Server CVE-2020-1350 RCE Indicators via Suspicious Child Process Creation
Alerts on non-benign subprocesses spawned by Windows DNS (dns.exe), consistent with CVE-2020-1350 exploitation attempts.
sigmacritical2020-07-15Windows Process Creation: regsvr32 Invoked to Load .ocx from AppData Roaming
Flags regsvr32 /s /i loading an .ocx from AppData\Roaming on Windows, a stealthy code-loading technique.
sigmacritical2020-07-10Citrix ADC/ADS Exploitation Attempts Targeting RAPI and PCIDSS Paths (CVE-2020-8193/8195)
Flags Citrix ADC/NetScaler HTTP requests whose URI queries match exploitation-related patterns for CVE-2020-8193 and CVE-2020-8195.
sigmacritical2020-07-10Windows Registry Run Key Modification for ntkd Persistence
Flags Windows registry activity hitting the Run key path segment "\Run\ntkd" used for automatic startup persistence.
sigmacritical2020-07-07Web Exploitation Attempt Pattern for CVE-2020-5902 on F5 BIG-IP (URI Traversal)
Alerts on web requests with query patterns consistent with CVE-2020-5902 exploitation attempts targeting F5 BIG-IP.
sigmacritical2020-07-05Windows Registry Markers for FlowCloud Malware Configuration and Keylogger Components
Detects registry activity referencing specific HARDWARE marker GUID keys and the Setup\PrintResponsor path on Windows.
sigmacritical2020-06-09Confluence CVE-2019-3398 Web Exploitation via Path Traversal Upload POST Request
Alert on Confluence POST /upload.action requests with query-based path traversal filename patterns consistent with CVE-2019-3398.
sigmacritical2020-05-26Windows process command lines matching May 2020 Turla ComRAT command patterns
Triggers on Windows command lines matching a set of Turla-related indicators documented by ESET (May 2020).
sigmacritical2020-05-26Windows: Process executions matching Greenbug espionage tool indicators
Alerts on Windows process creation with command-line patterns matching PowerShell execution-policy bypass and reverse-shell related tooling.
sigmacritical2020-05-20Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
sigmacritical2020-05-08Proxy Downloads Containing /pwndrop/ (PwnDrp Web Server)
Alerts on proxy requests to URIs containing '/pwndrop/', consistent with PwnDrp-style web delivery.
sigmaWebcritical2020-04-15Microsoft Exchange Web RCE Attempts via GET Requests Containing ECP/OWA and __VIEWSTATE
Alerts on web requests to Exchange ECP/OWA that include __VIEWSTATE= in the query.
sigmacritical2020-02-29Windows Process Creation: Sticky Keys Backdoor via sethc.exe Replacement
Flags forced replacement of C:\Windows\System32\sethc.exe with cmd.exe consistent with a Sticky Keys backdoor.
sigmaWindowscritical2020-02-18Windows: Dumpert Process Dumper Execution via Dumpert.dll or Known MD5
Detects Dumpert execution on Windows via known hash and command line reference to Dumpert.dll for lsass memory dumping.
sigmaWindowscritical2020-02-04Windows File Creation of Dumpert Default Dump (dumpert.dmp)
Alerts on creation of Dumpert’s default "dumpert.dmp" dump file on Windows.
sigmaWindowscritical2020-02-04Windows process activity matching Winnti malware traits from ProgramData\DRM paths
Detects suspicious Winnti-like execution where ProgramData\DRM processes spawn specific child binaries with known parent path patterns.
sigmacritical2020-02-01Windows Audit-CVE: User Applications Writing CveEventWrite Events (Event ID 1)
Alerts on Windows Audit-CVE EventID 1 entries from Microsoft-Windows-Audit-CVE provider indicating CveEventWrite activity.
sigmaWindowscritical2020-01-15Citrix NetScaler CVE-2019-19781 Attempted Exploitation via Web Requests
Flags suspicious NetScaler HTTP URIs containing traversal-style /vpns/ portal script or config file references.
sigmacritical2020-01-02