Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Registry: lsass.exe Creating Local Hidden User Account Entries
Alerts when lsass.exe writes hidden local user name entries to the SAM\...\Users\Names\ registry path.
sigmaWindowshigh2021-05-03Windows Security: Hidden Local User Account Creation (Event ID 4720)
Alerts on Windows 4720 local user creation for hidden accounts (username ending with '$'), excluding 'HomeGroupUser$'.
sigmaWindowshigh2021-05-03Windows Process Access to svchost.exe with Credential Dumping Access Rights
Alerts on attempts to read svchost.exe memory consistent with credential dumping, excluding known benign callers.
sigmaWindowshigh2021-04-30Windows PowerShell Get-Process or aliases targeting LSASS (lsas)
Alerts on PowerShell Get-Process/alias commands referencing LSASS in Windows process creation events.
sigmaWindowshigh2021-04-23Windows PowerShell: Get-Process querying lsass within a ScriptBlock
Alerts when PowerShell ScriptBlock text runs Get-Process against lsass, a common credential-access precursor.
sigmaWindowshigh2021-04-23Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Flags HybridConnectionManager-initiated DNS queries to servicebus.windows.net on Windows.
sigmaWindowshigh2021-04-12Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)
Flags Windows Hybrid Connection Manager-related events mentioning sb:// and servicebus.windows.net.
sigmaWindowshigh2021-04-12Windows Security Event 4697: HybridConnectionManager Service Installation
Alerts on HybridConnectionManager service installation on Windows via Security Event ID 4697.
sigmaWindowshigh2021-04-12Windows Registry: Outlook Macro Security Level Set to Enable All Macros
Detects Outlook macro warning bypass by setting the Outlook security level registry value to enable all macros.
sigmaWindowshigh2021-04-05Windows Persistence: Outlook LoadMacroProviderOnBoot Registry Setting Modification
Alerts on enabling the Outlook LoadMacroProviderOnBoot registry setting, which can allow automatic VBA module loading at startup.
sigmaWindowshigh2021-04-05Windows Exchange Management: Set-OabVirtualDirectory ExternalUrl to script content
Detects Exchange Management changes to OAB ExternalUrl containing script indicators and Page_Load.
sigmaWindowshigh2021-03-15Windows schtasks.exe Creating One-Time Scheduled Tasks Using Temp Folder
Alerts on schtasks.exe commands that create one-time scheduled tasks referencing a Temp directory.
sigmaWindowshigh2021-03-11Windows: Suspicious Service Binary Executed from Public/System Directories
Alerts on service-hosted processes executing from user/public or system-writable directories on Windows.
sigmaWindowshigh2021-03-09Windows Registry: VBScript/HTMLApplication Payload Stored Under Run Keys
Flags registry persistence where script payload indicators like vbscript: and RunHTMLApplication appear in set registry values.
sigmaWindowshigh2021-03-05Windows Process Creation: rundll32.exe Command Line Invoking .sys Files
Flags Windows rundll32.exe executions whose command line references .sys file patterns.
sigmaWindowshigh2021-03-05Windows rundll32 Executing Inline VBScript via RegRead
Detects rundll32.exe command lines containing inline VBScript execution with RegRead and window.close.
sigmaWindowshigh2021-03-05Windows Process Command Line: Suspicious Inline VBScript with UN2452-Like Keywords
Alerts on Windows command lines containing inline VBScript keywords and registry access indicators matching the UNC2452 UN2452 pattern.
sigmahigh2021-03-05Windows Process Creation: Exchange PowerShell Snap-in Loading via Add-PSSnapin
Flags PowerShell executions that Add-PSSnapin Exchange snap-ins, consistent with Exchange mailbox/config data collection.
sigmaWindowshigh2021-03-03Windows PowerShell TcpClient reverse-shell connection attempt via Net.Sockets
Alerts on PowerShell processes launching with .NET TcpClient stream/write patterns consistent with reverse TCP connectivity.
sigmaWindowshigh2021-03-03Microsoft Exchange exploitation attempt via suspicious POST requests in web server logs
Flags POST traffic to Exchange OWA/ECP-related URLs with specific client and user-agent indicators consistent with exploitation attempts.
sigmahigh2021-03-03