Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation
Looks for Print Spooler plug-in/module load errors in Windows logs that may indicate CVE-2021-1675 exploitation attempts.
sigmahigh2021-06-30Windows Registry Service Install Indicators for Cobalt Strike Staging
Identifies suspicious Windows service installation registry writes tied to ADMIN$/.exe and %COMSPEC% start powershell patterns.
sigmaWindowshigh2021-06-29Pulse Connect Secure web exploitation attempts for CVE-2021-22893
Detects web requests to Pulse Connect Secure with URI query patterns consistent with CVE-2021-22893 exploitation attempts.
sigmahigh2021-06-29AWS CloudTrail: Security Hub findings evasion via finding updates or deletions
Identifies Security Hub finding and insight modifications (update or delete) that may impair detection results.
sigmaCloudhigh2021-06-28Windows Process Creation: WMIC.exe ActiveScriptEventConsumer Creation Attempt
Alerts on WMIC.exe command lines attempting to create an ActiveScriptEventConsumer for event-driven script execution.
sigmaWindowshigh2021-06-25Zeek x509: Default Cobalt Strike certificate serial observed in HTTPS traffic
Flags Zeek x509 certificates used in HTTPS when the certificate serial matches a known default Cobalt Strike value.
sigmaNetworkhigh2021-06-23Windows: Detect execution of renamed megasync.exe (original MegaSync) via process creation
Flags process launches where megasync.exe appears under a renamed or nonstandard execution context based on process creation fields.
sigmaWindowshigh2021-06-22Windows: Suspicious Child Process Spawned by scrcons.exe (Script Event Consumer)
Alerts on rare child processes spawned by scrcons.exe, which may indicate abuse of Script Event Consumer for execution.
sigmaWindowshigh2021-06-21Windows Registry: New TaskCache entry created by unusual process image
Alerts when TaskCache registry entries are created by processes other than a defined set of expected Windows binaries.
sigmaWindowshigh2021-06-18Windows process and registry activity matching SOURGUM persistence/privilege escalation behavior
Alerts on Windows process activity referencing specific system/IME WimBoot files and registry 'reg add' changes targeting HKLM CLSID inprocserver32.
sigmahigh2021-06-15Windows Registry Set—Custom Outlook Today Page for Persistence
Flags registry writes that configure a custom Outlook Today URL using Outlook Today registry values.
sigmaWindowshigh2021-06-10Windows Persistence Attempt Using Outlook.exe to Create Outlook Forms Cache
Flags Outlook (outlook.exe) form file activity targeting local FORMS directories often used for persistence.
sigmaWindowshigh2021-06-10Windows Registry Changes for Outlook WebView Home Page URL Persistence
Alerts on Windows registry modifications affecting Outlook WebView home page URL settings.
sigmaWindowshigh2021-06-09Windows Registry: Microsoft Office Protected View Disabled via Security Policy Keys
Flags Windows registry updates that disable Microsoft Office Protected View for attachments, internet files, UNC paths, or unsafe locations.
sigmaWindowshigh2021-06-08Windows MSExchange: Failed Transport Agent Installation (Install-TransportAgent)
Alerts on EventID 6 Exchange management events that include "Install-TransportAgent", indicating a failed Transport Agent installation attempt.
sigmaWindowshigh2021-06-08Windows AMSI Provider Registry Key Deletion (HKLM\Software\Microsoft\AMSI)
Alerts on deletion of AMSI provider registry key entries under HKLM\Software\Microsoft\AMSI, potentially indicating AMSI inspection impairment.
sigmaWindowshigh2021-06-07PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
sigmaWindowshigh2021-06-07Windows Sysmon Configuration Event Where Sysmon Stops
Alert on Sysmon status showing a stop event concurrent with a Sysmon configuration state change.
sigmaWindowshigh2021-06-04Windows Sysmon error events indicating service configuration update failures
Flags Windows Sysmon errors for failed service configuration/driver update attempts that may indicate tampering.
sigmaWindowshigh2021-06-04Windows Process Creation: SDelete Used for File Overwrite
Alerts when sdelete.exe runs in a way consistent with file overwrite to impede forensic recovery.
sigmaWindowshigh2021-06-03