Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Non-privileged reg.exe or PowerShell registry service configuration changes on Windows
Flags non-admin reg.exe or PowerShell activity targeting service registry configuration paths on Windows.
sigmaWindowshigh2020-10-05Windows Process Creation: Hydra Password Bruteforce Command-Line Parameters
Alerts when Windows process command lines include Hydra -u/-p parameters with USER/PASS placeholders.
sigmaWindowshigh2020-10-05Windows COM Hijack by Registry DelegateExecute Modification (HKCU Classes Folder\shell\open\command)
Flags HKCU DelegateExecute registry changes for COM hijack style persistence under the Folder shell open command.
sigmaWindowshigh2020-09-27Detect Wannacry killswitch DNS queries to hardcoded domains
Flags DNS lookups for known WannaCry killswitch domain strings and variants.
sigmaNetworkhigh2020-09-16Windows NetLogon Secure Channel Connection Allowed for Vulnerable Client
Alerts on Windows NetLogon ETW events indicating an allowed secure channel connection (Event ID 5829).
sigmaWindowshigh2020-09-15Windows Defender Windefend AMSI Detection (Event ID 1116)
Flags Windows Defender AMSI detections via windefend Event ID 1116 with SourceName set to AMSI.
sigmaWindowshigh2020-09-14Windows Process Creation: MpCmdRun.EXE Used to Download Files via DownloadFile url
Alerts when MpCmdRun.exe is executed with DownloadFile and url, indicating Defender utility file download behavior.
sigmaWindowshigh2020-09-04Windows Process Creation Indicators for Snatch Ransomware Word Document Droppers
Alerts on Windows process command lines showing instant safe-mode shutdown/reboot and stopping SuperBackupMan service.
sigmahigh2020-08-26Zeek: Public RDP Connections from Non-Private IPv4/IPv6 Ranges
Alert on Zeek-observed RDP connections originating from non-excluded IP ranges, suggesting external accessibility.
sigmaNetworkhigh2020-08-22Windows Security Event 5145: SMB Write Access to Admin Share (C$)
Flags non-machine accounts writing via SMB to the C$ administrative share using Security EventID 5145.
sigmaWindowshigh2020-08-06Webserver logs: Webshell ReGeorg indicators in POST URI query with null Referer/User-Agent
Flags HTTP POST requests with null referer/user-agent and ReGeorg-like URI query parameters in web logs.
sigmaWebhigh2020-08-04Windows TAIDOOR RAT DLL Load via rundll32 Command Line
Detects Windows process creation command lines consistent with TAIDOOR RAT DLL loading through rundll32.exe.
sigmahigh2020-07-30Windows windefend Event ID 5012: Windows Defender virus scanning disabled
Flags when Windows Defender disables virus scanning via windefend Event ID 5012.
sigmaWindowshigh2020-07-28Windows windefend: Windows Defender threat detection and mitigation events
Alerts on windefend events indicating Windows Defender malware detection and potential remediation activity.
sigmaWindowshigh2020-07-28Windows windefend EventID 5001: Windows Defender real-time protection disabled
Flags windefend Event ID 5001 indicating Windows Defender real-time protection was disabled.
sigmaWindowshigh2020-07-28Windows windefend: Microsoft Defender malware and PUA scanning disabled (Event ID 5010)
Flags Windows Defender disabling malware and PUA scanning using Windefend Event ID 5010.
sigmaWindowshigh2020-07-28Windows Defender antimalware grace period expired (Event ID 5101)
Alerts when Windows Defender signals its antimalware grace period expired via windefend Event ID 5101.
sigmaWindowshigh2020-07-28Windows webserver-spawned recon commands probing scripting tool help (perl/python/wget)
Flags webserver child processes running perl/python/python3/wget help commands to probe available tooling on the host.
sigmaWindowshigh2020-07-22Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
sigmaWindowshigh2020-07-14Windows Sysmon Operational Channel Reference Deleted via Security Event
Detects Security log events showing Sysmon Operational channel being disabled via channel reference deletion-like changes.
sigmaWindowshigh2020-07-14