Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows renamed dctask64.exe execution via known IMPHASH values
Flags Windows process creations where a renamed dctask64.exe execution matches known IMPHASH values.
sigmaWindowshigh2020-01-28Windows Process Creation: Detect dctask64.exe with Endpoint Central Execution/Injection Flags
Alerts on Windows execution of ManageEngine Endpoint Central dctask64.exe with specific hash and suspicious command-line indicators.
sigmaWindowshigh2020-01-28Windows MSTSC Shadowing CommandLine Using shadow:
Flags Windows processes launching MSTSC with noconsentprompt and shadow: parameters consistent with RDP session shadowing.
sigmaWindowshigh2020-01-24AWS CloudTrail: AWS Config Delivery Channel/Recorder Disabled
Identifies CloudTrail actions that delete AWS Config delivery channels or stop the configuration recorder.
sigmaCloudhigh2020-01-21Windows Process Command Lines Using System32/SysWow64 Tasks Folder
Alerts on process command lines referencing the writable System32/SysWow64 Tasks folders with common file staging/copy primitives.
sigmaWindowshigh2020-01-13Windows Process: curl Download with HTTP Output Redirect and Command Chaining
Flags Windows commands where curl downloads over HTTP with -o and then executes via command chaining with '&'.
sigmaWindowshigh2020-01-13Windows: Koadic Command Prompt Invocation with /q /c chcp
Flags cmd.exe executions with /q /c and chcp in the command line, matching Koadic-style command parameters.
sigmaWindowshigh2020-01-12Windows Process Access to svchost.exe with High-Rights GrantedAccess
Alerts on high-privilege access to svchost.exe when process call context is UNKNOWN, excluding MSBuild-origin traffic.
sigmaWindowshigh2020-01-02Windows Process Creation: svchost.exe Spawned Without Command-Line Arguments
Flags svchost.exe process starts lacking command-line values, excluding rpcnet/rpcnetp parent cases.
sigmaWindowshigh2019-12-28Windows CreateMiniDump.exe HackTool Execution via Process Creation
Detects the execution of CreateMiniDump.exe using image name and a specific IMPHASH.
sigmaWindowshigh2019-12-22Windows Process Execution of Bloodhound/SharpHound Command-Line Collection Options
Alerts on SharpHound/Bloodhound-like processes launching with discovery-focused command-line parameters.
sigmaWindowshigh2019-12-20Windows Security: checkadmin.exe TargetUserName starting with Administr (Event ID 4799)
Detects Windows Security Event 4799 where checkadmin.exe targets “Administr*” accounts, consistent with admin account enumeration.
sigmahigh2019-12-20Ursnif dropper download URLs matching PHP l= parameter ending in CAB
Flags proxy responses where a request URI contains /.php?l= and ends with .cab, returning HTTP 200.
sigmahigh2019-12-19Windows Process Execution Indicative of Ryuk-Style Ransomware Behavior
Flags suspicious Windows process command lines combining autorun persistence, public staging, file backup wiping, and service stoppage behavior.
sigmahigh2019-12-16Proxy access to raw paste endpoints on paste.ee and Pastebin-style services
Alerts on proxy requests for raw paste service URLs that can be used to stage or fetch malicious payloads.
sigmaWebhigh2019-12-05Windows ProcDump Execution via Renamed Binary
Flags renamed ProcDump usage on Windows by matching procdump indicators and dump flags while excluding known executable names.
sigmaWindowshigh2019-11-18Windows Security: Anonymous Logon (4624 LogonType 3) with Loopback IPs
Alerts on Windows 4624 LogonType 3 with ANONYMOUS LOGON and loopback IPs, matching RottenPotato-like patterns.
sigmaWindowshigh2019-11-15Windows Process Creation: Suspicious SetupComplete.cmd execution for CVE-2019-1378 exploitation
Alerts on cmd.exe parent command lines executing SetupComplete.cmd or PartnerSetupComplete.cmd from Windows Setup script paths.
sigmahigh2019-11-15Windows msiexec.exe Execution from Uncommon Directory
Alerts when msiexec.exe starts from a non-standard path, which may indicate masquerading.
sigmaWindowshigh2019-11-14Suspicious APT User-Agent Strings in Proxy Logs
Alerts when proxy requests contain known APT-style user agent strings indicating likely malicious client behavior.
sigmaWebhigh2019-11-12