Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
Windows Registry Access to WCESERVICE Start Key
Detects registry activity targeting the WCE service Start configuration in Windows.
sigmaWindowscritical2019-12-31Windows Process Execution of Windows Credential Editor (WCE) Executables
Flags execution of Windows Credential Editor (WCE.exe/WCE64.exe) using image name endings and known imphash values.
sigmaWindowscritical2019-12-31Ursnif C2 Proxy Traffic Identified by Base64 URI Encoding and .avi/.images Pattern
Flags proxy requests with Base64-like URI characters plus '/images/' and '.avi' patterns consistent with Ursnif C2.
sigmacritical2019-12-19Windows CVE-2019-1388 UAC Consent to Internet Explorer Execution as LOCAL_SYSTEM
Flags UAC consent.exe launching iexplore.exe running as SYSTEM, consistent with CVE-2019-1388 exploitation.
sigmacritical2019-11-20Webserver CVE-2019-11510 Exploitation Attempt via Guacamole URI
Alerts on web requests with a Guacamole-related URI query pattern associated with a Pulse Secure CVE-2019-11510 exploitation attempt.
sigmacritical2019-11-18Windows PowerShell: Silence EmpireDNSAgent script matches DNS tunnel and remote shutdown/restart activity
Flags PowerShell ScriptBlockText that combines Empire process-control indicators with dnscat DNS tunneling commands.
sigmaWindowscritical2019-11-01Windows Named Pipe Creation for Known Credential Dumping Tool Pipe Names
Alerts on Windows named pipe creations matching credential dumping tool pipe names.
sigmaWindowscritical2019-11-01Windows process creation: Suspicious Dtrack RAT ping and network recon commands
Alerts on Windows command-line reconnaissance patterns resembling Dtrack RAT activity.
sigmacritical2019-10-30Linux sudo CVE-2019-14287 exploit attempt via unusual USER strings
Alerts on sudo events with USER values matching patterns linked to CVE-2019-14287 exploit attempts.
sigmacritical2019-10-15Linux auditd: Webshell Remote Command Execution via execve/execveat (euid=33)
Alerts on execve/execveat executions by the web server user, consistent with potential webshell command execution.
sigmaLinuxcritical2019-10-12Windows WMI Backdoor in Exchange Transport Agent via WMI Event Filter Execution
Alerts when WMI-backed execution is launched under EdgeTransport.exe, excluding common Exchange and conhost false positives.
sigmaWindowscritical2019-10-11Windows Process Activity Indicative of QBot (WinRAR to wscript, ping/type, regsvr32)
Alerts on Windows process creation consistent with QBot-like script execution chains from WinRAR and regsvr32/tmp staging.
sigmacritical2019-10-01Windows Security: Detect WRITE_DAC on AD DS objects (Event ID 4662)
Flags AD DS Security Event 4662 activity indicating WRITE_DAC permission changes on domain objects.
sigmaWindowscritical2019-09-12Windows Process Creation: Empire PowerShell UAC Bypass CommandLine Pattern
Flags Windows process creation events running Empire-style PowerShell UAC bypass command fragments.
sigmaWindowscritical2019-08-30Windows Security: AD object replication attempted by non-machine account (Event ID 4662)
Alerts on AD replication-related object access events where the requester is not a machine account.
sigmaWindowscritical2019-07-26Windows Registry: Create/Modify CLSID/AppX keys associated with OceanLotus decoy paths
OceanLotus Registry Activity
sigmacritical2019-04-14Windows Process CommandLine contains -export dll_u (DLL export function load)
Flags Windows processes that invoke a DLL export function named dll_u via command-line export arguments.
sigmacritical2019-03-04Windows process activity matching WannaCry executables and ransom note text
Alerts on Windows process creation where WannaCry-related executables and the @Please_Read_Me@.txt command indicator appear.
sigmacritical2019-01-16Windows: NotPetya indicators via wevtutil log clearing, fsutil deletejournal, and rundll32 .dat/.zip.dll execution
Flags Windows process execution indicative of NotPetya: clearing event logs with wevtutil and deleting C drive USN journal with fsutil.
sigmacritical2019-01-16Windows Process Creation: Potential Dridex-Related Execution via svchost/regsvr32 and Recon Tools
Alerts on suspicious svchost.exe or regsvr32.exe process executions with matching command-line and parent/child patterns indicative of Dridex activity.
sigmacritical2019-01-10