Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Service Control Manager Rundll32 Obfuscation via Command-Line Encoded PowerShell
Detects service creation where ImagePath invokes rundll32 (shell32) with command-chain tokens indicative of obfuscated PowerShell.
sigmaWindowshigh2020-10-09Windows System: mshta Launches vbscript:createobject via Service Control Manager (Event ID 7045)
Flags Windows service creation (7045) where ImagePath includes mshta and vbscript:createobject.
sigmaWindowshigh2020-10-09Windows System: Suspicious Clip.exe Execution via Service Control Manager (Event ID 7045)
Alerts on Windows service creation starting clipboard/Clip.exe-related binaries via Service Control Manager ImagePath.
sigmaWindowshigh2020-10-09Windows Security 4697: Obfuscated command uses rundll32 with shell32.dll
Alerts on EventID 4697 service command lines containing rundll32 with shell32.dll/shellexec_rundll and obfuscation-like script fragments.
sigmaWindowshigh2020-10-09Windows Security EID 4697: mshta Used to Run Obfuscated VBScript PowerShell
Detects service creation where the binary path includes mshta plus VBS/automation indicators consistent with script-based obfuscation.
sigmaWindowshigh2020-10-09Windows Security 4697: Obfuscated PowerShell via use of Clip.exe from scripts
Alerts on EID 4697 service installations where the service file name matches Clip/clipboard indicators tied to obfuscated PowerShell.
sigmaWindowshigh2020-10-09Windows Process Execution: Obfuscated PowerShell Invocation Using mshta with VBScript CreateObject
Flags Windows process command lines containing an obfuscated PowerShell+MSHTA VBScript execution pattern.
sigmaWindowshigh2020-10-08PowerShell ScriptBlock Obfuscation via MSHTA VBScript CreateObject Execution
Alerts on PowerShell script blocks containing mshta and VBScript createobject/.run/window.close patterns consistent with obfuscated execution.
sigmaWindowshigh2020-10-08PowerShell Module: Obfuscated MSHTA Invocation via VBS CreateObject
Alerts when PowerShell module payload text includes an obfuscated MSHTA/VBScript invocation sequence.
sigmaWindowshigh2020-10-08UAC Bypass Using wsreset.exe Registry Command Path (Windows)
Identifies registry TargetObject values associated with a wsreset-style UAC bypass execution command path on Windows.
sigmaWindowshigh2020-10-07Windows Visual Basic vbc.exe Compiles to .obj via cvtres.exe Resource Converter
Alerts when vbc.exe spawns cvtres.exe during Windows VB command-line compilation activity.
sigmaWindowshigh2020-10-07Windows regedit.exe exports a registry key into an alternate data stream
Flags regedit.exe executions where the process image ends with '\regedit.exe', consistent with exporting Registry data to an alternate data stream.
sigmaWindowshigh2020-10-07PowerShell Service Persistence via Registry ImagePath on Windows
Flags Windows registry service ImagePath entries that reference PowerShell (powershell/pwsh).
sigmaWindowshigh2020-10-06Windows: Time Travel Debugging Utility (tttracer.exe) Process Execution
Alerts when tttracer.exe is the parent process of a spawned process on Windows.
sigmaWindowshigh2020-10-06PowerShell Script Block WinAPI Calls Indicative of Injection or Token Abuse (Windows)
Detects PowerShell ScriptBlocks containing WinAPI function-name combinations consistent with injection and token manipulation.
sigmaWindowshigh2020-10-06Windows UAC Bypass via dism.exe Loading Fake dismcore.dll
Alerts when dism.exe loads a dismcore.dll that is not the expected System32 Dism DLL.
sigmaWindowshigh2020-10-06Windows Time Travel Debugging DLL Loads (ttdrecord/ttdwriter/ttdloader)
Flags Windows image loads of Time Travel Debugging Utility DLLs (tdrecord/tdwriter/tdloader), often abused for stealthy credential dumping.
sigmaWindowshigh2020-10-06Windows PowerShell Remote Thread Into lsass.exe Suggesting Credential Dumping
Alerts when PowerShell creates a remote thread into lsass.exe, indicating possible credential dumping on Windows.
sigmaWindowshigh2020-10-06PowerShell Script Execution via Windows Service Creation (Service Control Manager)
Flags service creation/start events where the service ImagePath references PowerShell (powershell/pwsh).
sigmaWindowshigh2020-10-06Windows Service Creation of PowerShell/Pwsh Scripts (Security EID 4697)
Alerts on service creation events where the service executable name includes powershell or pwsh.
sigmaWindowshigh2020-10-06