Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Empire C2 Proxy Requests with Specific User-Agent and POSTed PHP URIs
Flags proxy HTTP POSTs using an Empire-like user agent to specific admin/login PHP endpoints.
sigmaWebhigh2020-07-13Windows PowerShell Command Lines Containing [char]0x or (WCHAR)0x Obfuscation Syntax
Identifies PowerShell execution command lines using suspicious [char]0x or (WCHAR)0x encoding patterns.
sigmaWindowshigh2020-07-09Windows Process Execution of DIT Snapshot Viewer (ditsnap.exe)
Alerts on execution of the DIT snapshot viewer tool ditsnap.exe on Windows.
sigmaWindowshigh2020-07-04Windows desktopimgdownldr Suspicious URL and Registry Modification via Command Line
Flags desktopimgdownldr command lines indicating potential external file download or personalization registry deletion.
sigmaWindowshigh2020-07-03Windows curl.exe Suspicious Download to Local File Paths
Flags curl.exe executions on Windows that appear to download to local files in suspicious directories with risky file extensions.
sigmaWindowshigh2020-07-03Windows Desktop Image Downloader Targeting Lock Screen Images with Suspicious File Types
Alerts on desktopimgdownldr-style lock screen image target writes to non-system paths with suspicious filename characteristics.
sigmaWindowshigh2020-07-03Apache Guacamole Linux: Two-User Session Presence Anomaly
Flags Guacamole sessions on Linux when telemetry indicates two users are present, suggesting anomalous or suspicious session activity.
sigmaLinuxhigh2020-07-03Windows Registry Printer Driver Installations with Empty Manufacturer Field
Alerts on Windows registry printer driver environment updates where Manufacturer is set to empty.
sigmaWindowshigh2020-07-01Windows Registry Event Triggered by RedMimicry Winnti Playbook (HTMLHelp\data)
Alerts on Windows registry events targeting HKLM\SOFTWARE\Microsoft\HTMLHelp\data associated with the RedMimicry Winnti playbook.
sigmaWindowshigh2020-06-24Windows process execution matching Winnti RedMimicry playbook (rundll32/cmd with temp batch and gthread/sigcmm DLLs)
Flags rundll32.exe/cmd.exe launches with Winnti-specific DLL and temp batch indicators.
sigmaWindowshigh2020-06-24Windows File Drops Matching Winnti Dropper Artifacts (gthread/sigcmm DLLs, tmp.bat)
Detects Windows file drops of specific DLLs and a Windows Temp batch filename pattern associated with a Winnti dropper scenario.
sigmaWindowshigh2020-06-24Windows Process Creation: Detect reg.exe Add Control Panel CPL Items
Alerts on reg.exe adding Control Panel CPL items via CurrentVersion\Control Panel\CPLs, a common vector for stealthy execution/persistence.
sigmaWindowshigh2020-06-22Windows Process Creation: IE Security Registry Values Disabled via Command Line
Alerts on Windows command lines that set IE hardening-related registry values to disable security features.
sigmaWindowshigh2020-06-19Windows Registry Modification via Process Creation Command Lines Indicative of Ke3chang/TidePool
Alerts on Windows process command lines that set IE hardening and related Internet Explorer registry properties consistent with Ke3chang/TidePool.
sigmahigh2020-06-18Windows Process Creation: Possible Path Traversal in cmd.exe Command Line
Alerts on Windows cmd.exe executions with "../.." path traversal indicators in parent/child command lines.
sigmaWindowshigh2020-06-11Windows file indicators for Octopus Scanner malware artifacts
Alerts on Windows file activity for Octopus Scanner-related filenames (Cache134.dat, ExplorerSync.db) in AppData.
sigmaWindowshigh2020-06-09Windows Registry Changes Indicating Suspicious Camera/Microphone Capability Access
Alerts on Windows consent-store registry entries showing webcam/microphone access tied to Temp or public user paths.
sigmaWindowshigh2020-06-07Sysmon Registry: .NET ETWEnabled Disabled via COMPlus ETW Flags
Alerts on Sysmon registry sets that set .NET ETWEnabled/COMPlus ETW flags to 0, impairing ETW-based telemetry.
sigmaWindowshigh2020-06-05Windows Registry ETW Logging Disabled for .NET via Security Event 4657
Alerts when .NET ETW logging is disabled via registry changes (ETWEnabled or COMPlus ETW settings) using Event ID 4657.
sigmaWindowshigh2020-06-05Windows Process Creation: Detect Covenant PowerShell Launcher Command Lines
Identifies Windows PowerShell command lines commonly used by Covenant launchers, including hidden/encoded execution patterns.
sigmaWindowshigh2020-06-04