Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Windows AppX Execution of Sysinternals Tools (procdump/psloglist/psexec/livekd/ADExplorer)
Flags execution of common Sysinternals binaries when launched through the Windows AppX runtime.
sigmaWindowslow2023-01-16PowerShell script alias obfuscation via -Value (-join(...))
Flags PowerShell script blocks that set aliases using -Value with a (-join(...)) character-joining obfuscation pattern.
sigmaWindowslow2023-01-09Juniper BGP Logs: Missing MD5 Digest in Route Authentication
Flags Juniper BGP log messages indicating a missing MD5 digest, highlighting potential exposure from unauthenticated routing sessions.
sigmaNetworklow2023-01-09Huawei BGP Authentication Failures Indicating Failed Session Attempts
Flags Huawei BGP authentication failure log events that may indicate credential attempts or routing manipulation.
sigmaNetworklow2023-01-09Cisco LDP MD5 Authentication Failure Events
Flags Cisco LDP TCP MD5 authentication failure events that may indicate brute-force attempts to affect MPLS label signaling.
sigmaNetworklow2023-01-09Cisco BGP Authentication Failure Events Indicating Potential Credential Attacks
Flags Cisco BGP authentication failure events associated with TCP/179 traffic that may indicate credential abuse.
sigmaNetworklow2023-01-09Windows PowerShell Script Block Alerts for Set-Alias and New-Alias Usage
Alerts on PowerShell scripts that create aliases via Set-Alias/New-Alias, a common obfuscation technique, using ScriptBlockText logging.
sigmaWindowslow2023-01-08AWS CloudTrail: Potential S3 Bucket Enumeration via ListBuckets by Non-AssumedRole
Identifies S3 ListBuckets calls in CloudTrail that are not from assumed-role identities, which may indicate bucket discovery activity.
sigmaCloudlow2023-01-06Linux auditd: Access to hidden files or hidden directories (/. paths)
Alerts when Linux auditd shows PATH values referencing hidden files or hidden directories (excluding common dev/cache paths).
sigmaLinuxlow2022-12-30Linux Privilege Capability Discovery via getcap
Flags Linux executions of /getcap with -r to recursively enumerate file capabilities during discovery.
sigmaLinuxlow2022-12-28Windows ETW Logging Disabled via SCM Registry TracingDisabled Key
Detects SCM ETW logging being disabled by setting the TracingDisabled registry DWORD for services.exe.
sigmaWindowslow2022-12-09Windows Registry Change Disables ETW for rpcrt4.dll via ExtErrorInformation
Flags Windows registry updates that disable ETW logging for rpcrt4.dll through ExtErrorInformation.
sigmaWindowslow2022-12-09Windows Defender SubmitSamplesConsent Disabled (Real-Time Protection)
Flags Windows Defender configuration changes disabling automatic sample submission (SubmitSamplesConsent=0x0).
sigmaWindowslow2022-12-06Windows Security Event Add/Remove Computer Account (4741/4743)
Alerts on Windows domain computer account create/delete activity via Security event 4741 and 4743.
sigmaWindowslow2022-10-14Windows Driver Load of Known Vulnerable Drivers by File Name
Alerts when Windows loads a driver whose filename matches a list of known vulnerable drivers.
sigmaWindowslow2022-10-03Process Creation: curl on Linux
Flags Linux process starts for the curl binary, indicating potential remote file download or web requests.
sigmaLinuxlow2022-09-15Windows Suspicious Process Execution Using GUID-Like Folder Names in %TEMP% or AppData
Hunts Windows processes whose command lines reference GUID-named folders in user AppData/Temp locations.
sigmalow2022-09-01Windows: DirLister.exe Execution for Directory Listing Discovery
Alerts on execution of DirLister.exe on Windows, indicating potential directory/file discovery activity.
sigmaWindowslow2022-08-20Windows DNS Query for _ldap.* Using LDAP-Related Discovery
Alerts on _ldap.* DNS queries from uncommon Windows processes, indicating potential LDAP/DNS service discovery.
sigmaWindowslow2022-08-20Windows: User Profiles Service EventID 1511 indicating potential CVE-2022-21919 or CVE-2021-34484 LPE
Alerts on User Profiles Service Event ID 1511, a possible signal of LPE exploitation attempts associated with CVE-2022-21919 or CVE-2021-34484.
sigmalow2022-08-16