Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
PowerShell Module: Obfuscated Environment Variable Expansion via cmd /c set -f Pattern
Alerts when PowerShell module payloads obfuscate execution via cmd /c|/r and environment-variable-based set patterns.
sigmaWindowshigh2020-10-15PowerShell Module: Obfuscated STDIN Execution via cmd /c or cmd /r
Alerts when an obfuscated cmd->PowerShell payload uses stdin-style input and noexit/no-execution patterns.
sigmaWindowshigh2020-10-15Windows Service Control Manager: Obfuscated Environment Variable PowerShell via cmd /c set -f
Alerts on Service Control Manager event 7045 where a service ImagePath uses cmd /c|/r with "set" and -f formatting.
sigmaWindowshigh2020-10-15Windows System Service Control Manager spawning cmd with PowerShell and stdin input obfuscation
Flags SCM-created services whose ImagePath runs cmd to invoke PowerShell using stdin/input and -NoExit patterns.
sigmaWindowshigh2020-10-15Windows Security 4697: cmd.exe Launching Obfuscated PowerShell via Environment Variable Expansion
Alerts on EID 4697 service installation command lines containing obfuscated cmd.exe SET patterns used to execute PowerShell via environment variables.
sigmaWindowshigh2020-10-15Windows Security Event 4697 PowerShell Launch via cmd/stdin Obfuscation
Alerts on service creation events that run PowerShell through cmd with stdin-style obfuscation markers.
sigmaWindowshigh2020-10-15Linux: Grep used to search for passwords in files (auditd EXECVE)
Flags Linux process executions running grep with “password” in the command line.
sigmaLinuxhigh2020-10-15Windows Script and LOLBins Loading .NET CLR DLLs via clr.dll, mscoree.dll, mscorlib.dll
Alerts when common scripting/execution binaries load .NET CLR DLLs like clr.dll and mscoree.dll on Windows.
sigmaWindowshigh2020-10-14Windows Registry-Based DLL Hijack via WAB.EXE Using WAB Registry DLLPath
Flags WAB.EXE DLLPath registry writes where the configured DLL path differs from the default.
sigmaWindowshigh2020-10-13Windows manage-bde.wsf via wscript/cscript Proxy Execution
Flags Windows process executions where wscript/cscript runs manage-bde.wsf, indicating potential proxy execution via LOLBIN.
sigmaWindowshigh2020-10-13Windows Process Command Line: Detect VAR++ LAUNCHER Obfuscated PowerShell
Flags Windows command lines showing VAR++ launcher-style obfuscated PowerShell execution through Invoke-Expression patterns.
sigmaWindowshigh2020-10-13Windows Process Creation: Obfuscated Cmd Uses clip.exe to Execute PowerShell
Alerts when cmd.exe uses obfuscated Clip.exe/clipboard calls to launch PowerShell.
sigmaWindowshigh2020-10-13Detect VAR++ LAUNCHER-Style Obfuscated PowerShell Command Block
Detects VAR++ LAUNCHER-like PowerShell obfuscation patterns in ScriptBlockText.
sigmaWindowshigh2020-10-13PowerShell Script Block Obfuscation via cmd/clipboard and clip.exe execution
Identifies obfuscated PowerShell script blocks launching clip.exe and chaining clipboard-related execution.
sigmaWindowshigh2020-10-13PowerShell Module: VAR++ LAUNCHER Obfuscation in Obfuscated Command Payload
Identifies obfuscated PowerShell module payloads matching a VAR++ LAUNCHER-style invocation pattern.
sigmaWindowshigh2020-10-13PowerShell Module: Obfuscated Clip.exe launcher using cmd with clipboard download payload
Detects obfuscated PowerShell module commands that run cmd with clip.exe/clipboard payload formatting.
sigmaWindowshigh2020-10-13Windows System: Detects Service Control Manager spawning obfuscated PowerShell via VAR++ LAUNCHER
Flags newly created Windows services whose ImagePath contains cmd chaining and obfuscated PowerShell launcher indicators.
sigmaWindowshigh2020-10-13Windows System Service Control: Obfuscated cmd Launching clip.exe for PowerShell
Flags service creation (Event 7045) with obfuscated cmd ImagePath using clip.exe/clipboard PowerShell execution patterns.
sigmaWindowshigh2020-10-13Windows Security 4697 Alert for Obfuscated PowerShell Invoke via VAR++ LAUNCHER
Alerts on obfuscated PowerShell launcher patterns in Windows service creation events (EID 4697) consistent with VAR++ LAUNCHER.
sigmaWindowshigh2020-10-13Windows Security Log: Obfuscated cmd Execution of clip.exe via PowerShell Clipboard Patterns (EID 4697)
Alerts on service creation (Windows 4697) with CLIP.exe command-line patterns that indicate obfuscated PowerShell execution.
sigmaWindowshigh2020-10-13