Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
sigmaWindowshigh2021-06-03Windows Rundll32 Used to Start Cobalt Strike DLL Load via StartW
Alerts on rundll32.exe command lines that include a .dll and StartW function, consistent with Cobalt Strike DLL loading.
sigmaWindowshigh2021-06-01Nginx service core dump after worker crash (signal 6)
Flags Nginx worker crashes that end with signal 6 core dumps, which may indicate serious issues or exploitation.
sigmaWebhigh2021-05-31Windows rundll32.exe Started Without Command-Line Parameters
Alerts on Windows process launches of rundll32.exe with no parameters, excluding likely benign parent paths.
sigmaWindowshigh2021-05-27Windows: regedit.exe launched with TrustedInstaller or Process Hacker parent
Alerts when regedit.exe is launched by TrustedInstaller.exe or ProcessHacker.exe.
sigmaWindowshigh2021-05-27Windows Service Control Manager: ProcessHacker service runs as LocalSystem
Flags Windows service installs for ProcessHacker-prefixed services running as LocalSystem.
sigmaWindowshigh2021-05-27Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
sigmaWindowshigh2021-05-26Linux PAM TTY Audit Enabling via /etc/pam.d Modification
Alerts on auditd-observed edits to PAM system-auth/password-auth tied to TTY input auditing.
sigmaLinuxhigh2021-05-24Windows Process Creation: PsExec/PAExec Flags Indicating SYSTEM Execution
Flags indicating PsExec/PAExec-style execution as LOCAL SYSTEM using cmd/powershell/pwsh in process command lines.
sigmaWindowshigh2021-05-22Windows Process Creation: Renamed PAExec Application Execution
Flags Windows executions of a renamed PAExec binary using process metadata and known IMPHASH values.
sigmaWindowshigh2021-05-22Wazuh CVE-2021-26814 RCE Exploitation via Directory Traversal in Web Requests
Detects Wazuh-related web requests attempting path traversal through the /manager/files query parameter.
sigmahigh2021-05-22Windows: WinRM Service Process Spawning Command-Line and Scripting Utilities
Flags suspicious child shells and admin utilities spawned by the WinRM host process (wsmprovhost.exe) on Windows.
sigmaWindowshigh2021-05-20PowerShell Script Block Logging: PowerView cmdlet names match
Alerts when PowerShell ScriptBlockText includes PowerView/PowerSploit reconnaissance cmdlet names tied to domain and access discovery.
sigmaWindowshigh2021-05-18Windows Process Command Lines Indicating ngrok.exe Tunnel Setup
Detects Windows executions of ngrok.exe with TCP/HTTP tunneling and authtoken/start-all YAML configuration patterns.
sigmaWindowshigh2021-05-14Windows: Detect Rclone command execution with exfiltration-oriented flags
Identifies likely rclone.exe exfiltration activity on Windows by matching command-line flags and rclone executable characteristics.
sigmaWindowshigh2021-05-10Windows whoami.exe Privilege Enumeration Using /priv Flag
Alerts on whoami.exe runs with /priv or -priv to enumerate current user privileges.
sigmaWindowshigh2021-05-05Linux Code Injection via ld.so Preload File (/etc/ld.so.preload)
Alerts on references to /etc/ld.so.preload, indicating possible dynamic-library injection persistence on Linux.
sigmaLinuxhigh2021-05-05Windows Pingback backdoor via ICMP C2 using updata.exe command-line parameters
Flags Windows process creation where updata.exe spawns msdtc config start auto commands consistent with Pingback backdoor.
sigmahigh2021-05-05Windows DLL Loading of C:\Windows\oci.dll by msdtc.exe
Flags msdtc.exe loading C:\Windows\oci.dll, consistent with Pingback backdoor DLL loading behavior.
sigmahigh2021-05-05Windows File Indicator for Pingback Backdoor updata.exe Writing oci.dll
Alerts on updata.exe creating or modifying C:\Windows\oci.dll as a Pingback backdoor file indicator.
sigmahigh2021-05-05