Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Detect reg.exe Deletion of RunMRU Registry Key
Alerts on reg.exe commands that delete the RunMRU registry key, clearing Run dialog command history.
sigmaWindowshigh2025-09-25Windows Process Execution of EDR-Freeze Tool
Flags execution of EDR-Freeze on Windows using image-name and IMPhash matches associated with the tool.
sigmaWindowshigh2025-09-24Linux Process Creation: curl Exfiltration from Malicious NPM Package Webhook.site
Alerts on Linux curl command lines using -d to send data to a specific webhook.site endpoint, consistent with exfiltration.
sigmahigh2025-09-24Linux File Events: Malicious GitHub Workflow File Creation (shai-hulud-workflow*.yml/yaml)
Alerts on new .github/workflows YAML files named for Shai-Hulud, indicating potential malicious GitHub Actions persistence.
sigmahigh2025-09-24Windows Process Creation: WerFaultSecure.exe PPL Tampering with Dump/Impair Parameters
Alerts on WerFaultSecure.exe executions with PPL-related dump/impair command-line parameters that may target sensitive security protections.
sigmaWindowshigh2025-09-23Windows: Suspicious Velociraptor Child Process Execution Indicators
Alerts when Velociraptor.exe spawns specific child processes tied to tunneling, msiexec web installs, or PowerShell download commands.
sigmaWindowshigh2025-08-29Windows PowerShell Uninstall-WindowsFeature/Remove-WindowsFeature Removing Windows-Defender GUI
Detects PowerShell uninstall/removal commands targeting the Windows-Defender GUI feature.
sigmaWindowshigh2025-08-22Windows File Creation of .funksec Ransom Note Extension
Flags Windows file creations where the new filename ends with .funksec, consistent with FunkLocker-encrypted file naming.
sigmahigh2025-08-08Windows Process Creation: CrushFTP spawning PowerShell, CMD, and scripting tool execution
Detects CrushFTP launching PowerShell/CMD and related LOLBins with command patterns consistent with RCE exploitation behavior.
sigmahigh2025-08-01Windows Suspicious File Writes to SharePoint Web Server Extensions Layouts Directory
Alerts on cmd/powershell/w3wp writes of script or web asset files into SharePoint layouts (15/16 TEMPLATE/ LAYOUTS).
sigmaWindowshigh2025-07-24Windows: Suspicious Attachment File Created in Outlook Temp Directories
Alerts on creation of risky file types in Outlook attachment temporary folders used during email attachment handling.
sigmaWindowshigh2025-07-22Windows Process Creation: Indicators of SharePoint spinstall0.aspx Encoded Command Exploitation (CVE-2025-53770)
Alerts on w3wp.exe command lines containing encoded spinstall0.aspx and SharePoint template layout path indicators consistent with CVE-2025-53770 exploitation.
sigmahigh2025-07-21Windows: WinRAR/Rar.exe Writing Files to Startup Folder Locations
Alerts on WinRAR/Rar creating files under the Windows Startup folder, a common persistence attempt.
sigmaWindowshigh2025-07-16Windows Scheduled Task Creation via schtasks.exe Using sshd/ssh.exe for Tunnel Setup
Alerts when schtasks.exe creates scheduled tasks that invoke sshd.exe or ssh.exe with tunnel-related arguments.
sigmaWindowshigh2025-07-14Windows PowerShell sets Microsoft Defender threat severity default actions to Allow/NoAction
Alerts when PowerShell Set-MpPreference sets Defender threat-severity default actions to Allow or NoAction.
sigmaWindowshigh2025-07-11Windows reg.exe disables Defender WMI Autologger sessions by setting Start to 0
Flags reg.exe changing WMI Autologger Start for DefenderApiLogger/DefenderAuditLogger to 0, impairing ETW security logging.
sigmaWindowshigh2025-07-09Windows Process Execution: Remove Windows Defender Context Menu Registry Keys via reg.exe/PowerShell
Alerts on reg.exe/PowerShell deleting Defender context menu handler registry keys to remove right-click scanning.
sigmaWindowshigh2025-07-09Windows Registry Set: FileFix-style Command Evidence in TypedPaths url1
Flags Windows registry TypedPaths url1 updates containing URL fragments and command/script keywords consistent with FileFix behavior.
sigmaWindowshigh2025-07-05Windows Process Creation: HollowReaper.exe Execution for Process Hollowing
Flags execution of HollowReaper.exe, a process hollowing shellcode launcher associated with stealth payload execution.
sigmaWindowshigh2025-07-01Windows Doppelganger (Doppelanger.exe) LSASS Dump Tool Execution
Alerts on Windows execution of Doppelganger.exe with matching IMPHASH values associated with LSASS dumping.
sigmaWindowshigh2025-07-01