Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Windows Security: Member Added to Security-Enabled Global Group
Alerts when Windows logs show a user was added to a security-enabled global group via Event ID 4728 or 632.
sigmaWindowslow2023-04-26Windows mstsc.exe launched with local .rdp file argument
Alerts on mstsc.exe executions that reference local .rdp files via the command line.
sigmaWindowslow2023-04-18Windows winget AppInstaller admin_settings registry modification via winget.exe
Detects winget.exe-driven changes to AppInstaller admin_settings in the registry under LocalState\admin_settings.
sigmaWindowslow2023-04-17Windows Service Terminated With Error (Service Control Manager Event 7023)
Alerts on Windows services terminated with an error as reported by the Service Control Manager (EventID 7023).
sigmaWindowslow2023-04-14Linux Bash Launched in Interactive Mode (-i)
Alerts when /bash is executed with the interactive flag (-i) on Linux.
sigmaLinuxlow2023-04-07Windows Registry Changes for Outlook Task/Note Reminder Trigger
Flags Windows registry writes under Outlook task/note keys consistent with an Outlook reminder being triggered.
sigmalow2023-04-05Suspicious Proxy Requests to IPFS URLs Containing Email Address
Alerts when proxy request URIs target IPFS and include an email address.
sigmaWeblow2023-03-16Windows AMSI.DLL Image Load by Uncommon Process Paths
Alerts when Amsi.dll is loaded by processes outside common Windows binaries and directories.
sigmalow2023-03-12Windows 7-Zip Extracts Password-Protected Archives via 7z/7za/7zr
Flags 7-Zip (7z/7za/7zr) command lines that include -p with x extraction and -o output, indicating password-protected archive extraction.
sigmalow2023-03-10Linux Package Removal via yum, apt, dpkg, or rpm Commands
Detects package uninstall activity on Linux via yum, apt/apt-get, dpkg, or rpm based on command-line removal flags.
sigmaLinuxlow2023-03-09Windows: Stop a Service with sc.exe via Process Creation (sc.exe stop)
Identifies sc.exe executions that include 'stop' to stop Windows services based on process creation and command line.
sigmaWindowslow2023-03-05Windows PowerShell Stop-Service Used to Stop a Service
Flags PowerShell executions that include the Stop-Service cmdlet to stop a Windows service.
sigmaWindowslow2023-03-05Windows: Service stop activity via net.exe command line
Flags Windows processes running net.exe/net1.exe with a command line containing ' stop ' to stop a service.
sigmaWindowslow2023-03-05Windows New Service Creation via sc.exe
Flags sc.exe service creation commands containing create and binPath on Windows, excluding Dropbox-launched cases.
sigmaWindowslow2023-02-20PowerShell Creates Windows Service via New-Service and -BinaryPathName
Flags PowerShell command lines that use New-Service with -BinaryPathName to create a Windows service.
sigmaWindowslow2023-02-20macOS: Guest account enabled via sysadminctl
Flags sysadminctl command lines that appear to activate the macOS guest account.
sigmamacOSlow2023-02-18Windows nltest.exe Execution for Network Information Discovery
Flags execution of nltest.exe (including nltestrk.exe via OriginalFileName) used for network and domain information discovery.
sigmaWindowslow2023-02-03GitHub Audit Log: Self-Hosted Runner Configuration Changes
Alerts on GitHub audit log events indicating self-hosted runner registration and runner group configuration changes.
sigmalow2023-01-27GitHub audit: New Actions secret created for org, environment, repo, or Codespaces
Triggers on GitHub audit events when an actor creates a new Actions secret for org, environment, Codespaces, or repo.
sigmalow2023-01-20Windows DNS Client: DNS queries containing "ufile.io"
Alerts on Windows DNS Client queries where the queried name includes "ufile.io".
sigmaWindowslow2023-01-16