Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process Masquerading: msdtc.exe and gpsvc.exe launched from Non-System Paths
Alerts on msdtc.exe or gpsvc.exe launched from paths outside Windows System32/SysWOW64.
sigmahigh2020-06-03Windows: Renamed Sysinternals DebugView Process Execution
Flags Windows executions labeled as Sysinternals DebugView when the image is not the original Dbgview.exe.
sigmaWindowshigh2020-05-28ComRAT Proxy HTTP Requesting index.php with h Parameter
Flags proxy HTTP requests with URIs containing /index/index.php?h=, consistent with web-based C2 behavior.
sigmahigh2020-05-26Windows netsh.exe Whitelists Allowed Program from Suspicious Path in Firewall
Flags netsh.exe firewall allow rules that whitelist a program located in suspicious Windows filesystem paths.
sigmaWindowshigh2020-05-25Windows RDP Port 3389 Allowed via netsh.exe Firewall Rule Creation
Flags netsh.exe commands that add firewall rules allowing TCP port 3389 (RDP).
sigmaWindowshigh2020-05-23Windows Registry: Office VBAWarning Disabled (VBAWarnings set to 1)
Alerts on Security\VBAWarnings being set to DWORD 0x00000001, enabling all Office VBA macros.
sigmaWindowshigh2020-05-22Windows Registry Set AccessVBOM DWORD=1 Disables Access Security for Access VBA
Alerts on Windows registry changes setting Security\AccessVBOM to DWORD 1, disabling VBA trust access to bypass Office warnings.
sigmaWindowshigh2020-05-22Windows: CrackMapExec PowerShell obfuscation via join/split static patterns
Flags Windows PowerShell executions with command-line obfuscation strings associated with CrackMapExec behavior.
sigmaWindowshigh2020-05-22Windows Network Connections Initiated by Notepad.exe
Alerts when notepad.exe initiates an outbound network connection, excluding typical printing traffic on port 9100.
sigmaWindowshigh2020-05-14Windows Registry Set: ServiceDll Path Ending with \CurrentControlSet\Services\wercplsupport\Parameters\ServiceDll
Alerts on Windows registry writes to a specific Services\wercplsupport\Parameters\ServiceDll target path.
sigmahigh2020-05-14Windows Persistence Attempt via sc config or wmic COR_PROFILER (Blue Mockingbird)
Flags sc.exe sc config and wmic.exe COR_PROFILER command lines tied to wercplsupporte.dll references.
sigmahigh2020-05-14Windows Registry Ports Key Changes with Script/Binary File Indicators
Flags registry modifications to the Ports key with path- or executable/script-like details that may indicate printer-based exploitation attempts.
sigmahigh2020-05-13Windows Process Creation: Add-PrinterPort Commands with Suspicious File Paths
Flags suspicious Add-PrinterPort usage referencing .exe/.dll/.bat or “Generic / Text Only” in Windows process command lines.
sigmahigh2020-05-13Windows: Detect rar.exe Archive Creation Using Password or Compression Options
Alerts on rar.exe command lines that include both password protection (-hp) and additional compression/archive flags.
sigmaWindowshigh2020-05-12Windows Office Startup Add-In Persistence via .wll/.xll/.xlam
Alerts on Office startup/add-ins DLL-based files (.wll/.xll/.xlam and related) written to Word/Excel startup paths.
sigmaWindowshigh2020-05-11Windows Security Log: Metasploit SMB NTLM Logon (4624/4625, 4776)
Detects Metasploit-linked NTLM SMB authentication activity using Windows 4624/4625 and 4776 with 16-char workstation names.
sigmaWindowshigh2020-05-06Windows Fax Service ualapi.dll Side-Loading via fxssvc.exe
Flags fxssvc.exe loading ualapi.dll from unexpected paths, indicating potential DLL side-loading for privilege escalation.
sigmaWindowshigh2020-05-04Windows Process Creation: .NET ETW Logging Environment Variables Set via Command Line
Flags process command lines setting COMPlus_ETWEnabled/COMPlus_ETWFlags, potentially impairing ETW logging for .NET.
sigmaWindowshigh2020-05-02Windows: Alert on Suspicious HH.EXE Process Execution
Alerts on HH.exe execution where the command line references temp, downloads, Outlook, or other writable directories.
sigmaWindowshigh2020-04-01Windows Process Creation: Suspicious Children Spawned by HTML Help (hh.exe)
Flags HH.exe spawning CertReq/CertUtil/CMD/PowerShell/cscript/regsvr32/mshta and other common Windows execution utilities.
sigmaWindowshigh2020-04-01