Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Suspicious Child Processes Spawned by sqlservr.exe
Alerts when SQL Server (sqlservr.exe) spawns suspicious command/system tools on Windows.
sigmaWindowshigh2020-12-11Windows Process Tree: rundll32.exe launching wermgr.exe via DllRegisterServer
Flags rundll32.exe spawning wermgr.exe where rundll32 command line includes DllRegisterServer.
sigmahigh2020-11-26Web server request pattern consistent with Oracle WebLogic CVE-2020-14882 exploitation
Detects WebLogic console exploitation attempts by matching encoded traversal patterns in HTTP URI query strings.
sigmahigh2020-11-02Windows Registry Run Key Modification via winekey or team9 backdoor
Detects registry Run key changes to "Backup Mgr" that may indicate persistence via winekey/team9.
sigmaWindowshigh2020-10-30Windows Image Load of PCRE.NET Package Temp Module Path
Alerts on Windows processes loading a temp module path tied to a PCRE.NET package component.
sigmaWindowshigh2020-10-29Windows Processes Creating PCRE.NET Temp Package Files
Identifies Windows processes writing temp files with a PCRE.NET package-specific path under AppData\Local\Temp.
sigmaWindowshigh2020-10-29Windows: Abused Debug Privilege via Command-Line Route/Add Spawned by System Parents
Flags PowerShell/cmd spawned by system processes with command lines containing both 'route' and 'ADD'.
sigmaWindowshigh2020-10-28Windows Process Creation: Default-Argument Invocation of Rundll32/WerFault/Regsvcs/Regasm/Regsvr32
Alerts on suspicious Windows process launches of key binaries with missing/empty arguments, excluding common Edge/Chromium installer use.
sigmaWindowshigh2020-10-23Windows Registry: Detect esentutl.exe activity under VSS service keys
Flags registry changes under VSS service keys when initiated by esentutl.exe, consistent with VSS-related abuse.
sigmaWindowshigh2020-10-20Windows: rundll32 Triggering comsvcs.dll MiniDump Against lsass.exe
Detects rundll32 invoking comsvcs.dll to dump lsass.exe via a MiniDump export.
sigmaWindowshigh2020-10-20macOS Process Creation: grep 'password' or laZagne Credential Extraction
Detects macOS executions of grep targeting 'password' strings and laZagne, suggesting local credential extraction attempts.
sigmamacOShigh2020-10-19macOS Process Execution: dd and truncate used for binary padding
Flags macOS dd plus truncate command lines consistent with adding junk data for binary padding.
sigmamacOShigh2020-10-19Windows PowerShell Script Execution via Redirected Input Stream
Flags PowerShell/pwsh executions where the command line includes redirected input ("- <").
sigmaWindowshigh2020-10-17Potential Windows Registry Persistence via AppCompatFlags TelemetryController Commands
Flags registry entries under TelemetryController\Command that reference executable/script payloads potentially abusing telemetry for persistence.
sigmaWindowshigh2020-10-16Windows sc.exe Security Descriptor Tampering to Deny Service Access via sdset
Alerts on sc.exe sdset commands that modify service security descriptors to deny access to critical trustees.
sigmaWindowshigh2020-10-16PowerShell command-line obfuscation indicators from special-character patterns (Windows)
Alerts on PowerShell executions whose command lines contain repeated special-character obfuscation patterns.
sigmaWindowshigh2020-10-15Windows Process Creation: Cmd Invokes PowerShell via Obfuscated Environment Variable Expansion
Alerts on cmd.exe command lines that use obfuscated environment-variable SET to execute PowerShell.
sigmaWindowshigh2020-10-15Windows Process Execution Using Obfuscated CMD to Pipe STDIN into PowerShell
Detects obfuscated cmd executions that launch PowerShell and reference $input/noexit patterns for STDIN-based execution.
sigmaWindowshigh2020-10-15PowerShell: Obfuscated invocation via Environment Variables in Script Block
Alerts on PowerShell script blocks launching cmd /c or /r with obfuscated set-and-{n} variable expansion patterns.
sigmaWindowshigh2020-10-15PowerShell Obfuscated stdin launcher using cmd /c or cmd /r patterns
Detects PowerShell script blocks that use obfuscated STDIN-driven cmd/powershell execution patterns.
sigmaWindowshigh2020-10-15