Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Exchange UMWorkerProcess File Drops Indicating CVE-2021-26858 Exploitation
Alerts on Exchange Unified Messaging (UMWorkerProcess.exe) creating unusual files, excluding common benign names consistent with CVE-2021-26858 activity.
sigmahigh2021-03-03Windows Process Creation: Suspected CVE-2021-26857 Exploitation via UMWorkerProcess.exe
Detects suspicious child process spawning by Exchange Unified Messaging (UMWorkerProcess.exe) associated with CVE-2021-26857 attempts.
sigmahigh2021-03-03Windows Process Creation: finger.exe Execution
Alerts on Windows executions of finger.exe, a legacy utility that may indicate suspicious reconnaissance or network activity.
sigmaWindowshigh2021-02-24Webserver POST to vROps uploadova endpoint indicative of CVE-2021-21972 exploitation
Alerts on POST requests to the uploadova endpoint tied to CVE-2021-21972 vSphere exploitation.
sigmahigh2021-02-24Webserver URI Detects DEWMODE Webshell Access Attempts
Identifies webserver requests with DEWMODE webshell-specific URI query parameter patterns.
sigmahigh2021-02-22Windows Process Creation: logman.exe Used to Stop or Delete ETW Trace Sessions
Alerts when logman.exe is used to stop or delete Windows ETW trace sessions.
sigmaWindowshigh2021-02-11Windows Process Creation: AdFind Executed with Suspicious Recon Flags
Detects AdFind executions on Windows that include common AD reconnaissance parameters.
sigmaWindowshigh2021-02-02Windows Audit Policy Tampering Using auditpol.exe Command-Line Flags
Flags auditpol.exe executions that disable, clear, remove, or restore Windows audit policy settings.
sigmaWindowshigh2021-02-02Windows Process Creation: Detect ShimCache Flush via rundll32 apphelp.dll/kernel32.dll
Flags rundll32 command-line activity that flushes ShimCache via apphelp.dll or kernel32.dll entry points.
sigmaWindowshigh2021-02-01Windows rundll32.exe execution with no parameters or arguments
Alerts on Windows rundll32.exe being started with an empty/no-parameter command line.
sigmaWindowshigh2021-01-31Windows WMIC Uninstall/Terminate Actions Targeting Security Products
Flags WMIC commands on Windows that attempt to uninstall or terminate security products or sensors using known vendor/product strings.
sigmaWindowshigh2021-01-30Windows Command-Line Disables Volume Shadow Copy (VSS) Snapshots
Flags Windows command lines that disable Volume Shadow Copy (VSS) snapshots via VSS Diag service switches.
sigmaWindowshigh2021-01-28Webserver Detection: SonicWall SSL VPN Jarrewrite Exploitation URI and User-Agent Payloads
Flags web requests to /cgi-bin/jarrewrite.sh with user-agent indicators consistent with command injection exploitation.
sigmahigh2021-01-25Webserver detection of TerraMaster TOS CVE-2020-28188 exploit requests
Flags GET requests to /include/makecvs.php with Event plus indicators of script download/execute behavior tied to CVE-2020-28188.
sigmahigh2021-01-25Windows Process Creation: 7z Archive Creation with Script/Command Launch Chaining
Flags Windows process creation chaining 7z archive commands with .zip plus .txt/.log extensions and wscript+rundll32 context.
sigmahigh2021-01-22Windows Process Creation: Raccine Removal via taskkill, registry and scheduled task deletion
Detects command-line activity that stops and removes Raccine components through process killing, registry deletion, and scheduled task removal.
sigmaWindowshigh2021-01-21Windows Service Installation (EID 4697) for SMB PsExec by Metasploit or Impacket
Alerts on Windows Event ID 4697 service installs matching SYSTEMROOT\8char.exe and on-demand start, consistent with PsExec-style SMB execution.
sigmaWindowshigh2021-01-21Windows Plink Remote Port Forwarding via -R Command Line
Alerts on Windows process command lines using Plink " -R " remote port forwarding to a local port.
sigmaWindowshigh2021-01-19Windows System Log: NTFS File System Driver Event 55 Indicates Possible NTFS Exploitation
Alerts on Windows NTFS Event ID 55 indicating a corrupted file record with a matching filename string in the event description.
sigmaWindowshigh2021-01-11Cisco ASA FTD web exploitation attempt matching CVE-2020-3452 with HTTP 200
Detects HTTP 200 requests targeting Cisco ASA/FTD web parameters associated with CVE-2020-3452 exploit behavior.
sigmahigh2021-01-07