Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Suspicious regsvr32 invocation by Notepad++ installer referencing NppShell.dll
Alerts when regsvr32 is run silently to register NppShell.dll but the regsvr32 image isn’t from standard Windows system locations.
sigmahigh2025-06-26Windows Process Creation: Command-Line Kerberos Coercion Signature via DNS SPN Spoofing
Alerts on Windows command lines containing 'UWhRCA' and 'BAAAA', a signature tied to Kerberos coercion via spoofed credential targeting.
sigmaWindowshigh2025-06-20Windows DNS Query with Kerberos Coercion Signature via DNS Object SPN Spoofing
Alerts on Windows DNS queries containing a base64-like credential target signature linked to Kerberos coercion via DNS spoofing.
sigmaWindowshigh2025-06-20Windows AD DNS Record Modification Indicators for Kerberos Coercion via SPN DNS Spoofing
Alerts on AD MicrosoftDNS DNS node changes whose DN contains a CREDENTIAL_TARGET_INFORMATION base64 marker tied to Kerberos coercion.
sigmaWindowshigh2025-06-20Zeek DNS detects base64 credential target pattern consistent with Kerberos DNS object spoofing
Alert on Zeek DNS queries containing the base64 Kerberos coercion signature pattern tied to CREDENTIAL_TARGET_INFORMATION.
sigmaNetworkhigh2025-06-20Windows DLL Load Trusted Path Bypass via Spoofed Directory Paths with Extra Space
Flags Windows DLL loads from spoofed "C:\Windows \\System32"-style paths with an extra space to indicate trusted-path bypass attempts.
sigmaWindowshigh2025-06-17Linux: Suspicious curl/wget Download to /tmp or /dev/shm Followed by sh -c Execution
Flags curl/wget retrieving content into /tmp or /dev/shm followed by immediate sh -c execution on Linux.
sigmaLinuxhigh2025-06-17Windows Process Creation: Possible CVE-2025-33053 WebDAV RCE via utility search-order manipulation
Flags suspicious child execution from WebDAV/UNC paths initiated by iediagcmd.exe or CustomShellHost.exe, consistent with CVE-2025-33053 exploitation.
sigmahigh2025-06-13Windows Process Access: Suspicious WebDAV target execution via iediagcmd.exe or CustomShellHost.exe (CVE-2025-33053)
Alerts when iediagcmd.exe or CustomShellHost.exe access WebDAV-hosted executables consistent with a potential RCE attempt.
sigmahigh2025-06-13Windows Process Creation: SharpSuccessor.exe Execution with Impersonation Parameters
Alerts on SharpSuccessor.exe command-line patterns indicative of Windows privilege escalation attempts.
sigmaWindowshigh2025-06-06Windows PowerShell Obfuscated COM MSI Installation via WindowsInstaller.Installer
PowerShell spawning that uses WindowsInstaller.Installer COM with obfuscated strings to call InstallProduct and suppress UI.
sigmaWindowshigh2025-05-27Linux: Disable ASLR via personality syscall or sysctl/randomize_va_space changes
Flags Linux events where ASLR is disabled using the personality syscall or sysctl setting kernel.randomize_va_space=0.
sigmaLinuxhigh2025-05-26Windows reg.exe Registry Save/Export of Third-Party Credential Paths
Alerts on reg.exe save/export commands targeting registry keys tied to third-party credential data.
sigmaWindowshigh2025-05-22Zeek HTTP: Suspicious User-Agent Containing "katz-ontop"
Alerts on Zeek HTTP sessions whose User-Agent includes "katz-ontop", a potential malware indicator.
sigmahigh2025-05-22DNS Queries to Katz Stealer–Associated Domains (Network)
Alerts on DNS queries for domains associated with Katz Stealer.
sigmahigh2025-05-22Windows DLL Load Indicators for Katz Stealer 2025 Variants
Alerts on Windows image loads of DLLs with Katz Stealer-associated names/paths.
sigmahigh2025-05-22Windows DNS Queries to Katz Stealer-Related Domains
Alerts on Windows DNS queries to domains associated with Katz Stealer malware infrastructure.
sigmahigh2025-05-22Windows RMM Tool MeshAgent Execution with Renamed MeshServiceName
Identifies renamed MeshAgent executions on Windows by matching --meshServiceName with OriginalFileName containing meshagent.
sigmaWindowshigh2025-05-19Windows Impacket-Pattern File Creation: sessionresume_[a-zA-Z]{8} Indicator
Flags Windows file creations of filenames matching Impacket sessionresume pattern ('sessionresume_<8 letters>').
sigmaWindowshigh2025-05-19macOS Process Creation: MeshAgent renamed execution via --meshServiceName
Identifies macOS executions of MeshAgent instances that include --meshServiceName, indicating potential renamed remote access tooling.
sigmamacOShigh2025-05-19