Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows PowerShell ScriptBlock containing WMImplant tool parameters
Alerts on PowerShell Script Block content containing WMImplant-related command and system-manipulation parameters.
sigmaWindowshigh2020-03-26Windows Process Creation: Java exploitation chain targeting Zoho ManageEngine Desktop Central (CVE-2020-10189)
Alerts on cmd/Pwsh/BITSAdmin and other command utilities launched by the Desktop Central Java runtime.
sigmahigh2020-03-25Windows PowerShell execution with uncommon/suspicious parent process
Alerts when PowerShell is started from certain unusual parent processes that commonly indicate abuse.
sigmaWindowshigh2020-03-20Zeek SMB Files: Impacket SecretDump Access to ADMIN$ and System32 .tmp Droppers
Alerts on Zeek SMB file events suggesting Impacket SecretDump-style staging in ADMIN$ under SYSTEM32 with .tmp files.
sigmaNetworkhigh2020-03-19Webserver Detection of POST Logupload Attempt for VMware View Planner CVE-2021-21978
Alerts on webserver POST requests targeting logupload/logMetaData parameters tied to CVE-2021-21978 probing.
sigmahigh2020-03-10Windows: Suspicious Execution of CSharp Interactive Console via PowerShell
Alerts when PowerShell launches csi.exe, indicating possible interactive .NET code execution.
sigmaWindowshigh2020-03-08Windows MMC20 Lateral Movement via MMC.exe -Embedding spawned by svchost.exe
Alerts when svchost.exe launches mmc.exe with “-Embedding”, indicating potential MMC20 COM-based lateral movement.
sigmaWindowshigh2020-03-04Windows: Detect Microsoft Exchange CVE-2020-0688 exploitation via Eventlog errors
Identifies Exchange Control Panel error events containing a ViewState parameter consistent with CVE-2020-0688 exploitation attempts.
sigmahigh2020-02-29Webserver Request Matching for CVE-2020-0688 Exploitation Attempt
Alerts when webserver URI queries include /ecp/default.aspx with __VIEWSTATEGENERATOR and __VIEWSTATE consistent with CVE-2020-0688 probing.
sigmahigh2020-02-27Detect Potential SQL Injection Payloads in GET URIs via Webserver Access Logs
Flags HTTP GET URIs containing SQL injection indicator strings in webserver access logs, excluding 404 responses.
sigmaWebhigh2020-02-22Windows: Office Application Loads VBE VBA DLLs via Image Load Events
Flags Office apps loading VBA-related VBE DLLs, a strong indicator of VBA macro execution.
sigmaWindowshigh2020-02-19Windows Office Apps Loading .NET GAC MSIL DLLs via Image Load Events
Alerts when an Office app loads a .NET DLL from the GAC_MSIL directory.
sigmaWindowshigh2020-02-19Windows Process Memory Dump via comsvcs.dll using rundll32
Alert on rundll32 loading comsvcs.dll with arguments consistent with a full process memory dump.
sigmaWindowshigh2020-02-18AWS CloudTrail: RestoreDBInstanceFromDBSnapshot Creates Public RDS Instance
Detects RDS restores from snapshots that result in a publicly accessible database instance in AWS CloudTrail.
sigmaCloudhigh2020-02-12AWS EC2 ModifyInstanceAttribute userData Startup Script Change
Detects CloudTrail EC2 userData startup script changes made via ModifyInstanceAttribute.
sigmaCloudhigh2020-02-12AWS GuardDuty CreateIPSet Trusted IP Set Changes (CloudTrail)
Alerts on CloudTrail GuardDuty CreateIPSet events that add or update trusted IP address sets.
sigmaCloudhigh2020-02-11Windows DNS analytic events for GALLIUM-related ddns QNAMEs (EventID 257)
Alert on Windows DNS analytical EventID 257 queries for GALLIUM-linked suspicious QNAMEs.
sigmahigh2020-02-07Windows Process Creation alerts on GALLIUM-associated hash IOCs
Flags Windows process executions where the file hash matches hardcoded GALLIUM-associated SHA256/SHA1 IOCs.
sigmahigh2020-02-07Windows: Flag SettingSyncHost.exe used to execute RoamDiag.cmd from cmd.exe
Flags non-System32/SysWOW64 processes spawned by SettingSyncHost.exe running RoamDiag.cmd via cmd.exe /c -outputpath.
sigmaWindowshigh2020-02-05PowerShell CommandLine Uses FromBase64String to Decode Base64 Content (Windows)
Detects PowerShell process creation where the command line includes ::FromBase64String(, indicating Base64 decoding.
sigmaWindowshigh2020-01-29