Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Proxy User-Agent Matching APT40 Dropbox Tool on api.dropbox.com
Alerts on proxy requests using a fixed Chrome 36 user-agent to api.dropbox.com.
sigmahigh2019-11-12Windows: Command-line contains long ab-prefixed string seen in TropicTrooper activity (Nov 2018)
Detects Windows processes whose command line contains a known TropicTrooper campaign indicator string.
sigmahigh2019-11-12Windows Process Creation: Detect Obfuscated PowerShell IEX Invocation from Invoke-Obfuscation
Detects PowerShell commands showing obfuscation markers consistent with Invoke-Obfuscation-powered IEX invocation.
sigmaWindowshigh2019-11-08PowerShell: Obfuscated IEX Invocation via Invoke-Obfuscation String/Variable Patterns
Alerts on obfuscated PowerShell IEX invocation strings built from Invoke-Obfuscation style concatenation patterns in ScriptBlockText.
sigmaWindowshigh2019-11-08PowerShell Module Obfuscated IEX Invocation via Invoke-Obfuscation Payload Patterns
Alerts when PowerShell module payloads contain patterns consistent with obfuscated IEX generation via Invoke-Obfuscation.
sigmaWindowshigh2019-11-08Windows System Service Creation of Obfuscated PowerShell IEX (Invoke-Obfuscation)
Flags Windows service creations whose ImagePath contains obfuscated PowerShell IEX invocation strings.
sigmaWindowshigh2019-11-08Windows Security: Detect Obfuscated PowerShell IEX Invocation via ServiceFileName Patterns (Event ID 4697)
Alerts on EventID 4697 instances where ServiceFileName matches obfuscated IEX-style PowerShell invocation patterns consistent with Invoke-Obfuscation.
sigmaWindowshigh2019-11-08Windows Credential Dump Tool Artifacts Written to Disk via File Events
Detects Windows file creation where the target filename contains or ends with known credential-dump tool or output names.
sigmaWindowshigh2019-11-01Windows Security: Suspicious Local Account Created with ANONYMOUS LOGON SamAccountName
Alerts on Windows local account creation where the new SamAccountName contains “ANONYMOUS” and “LOGON”.
sigmaWindowshigh2019-10-31Windows PowerShell Script Execution from Alternate Data Stream (ADS)
Flags PowerShell processes using Get-Content -Stream to execute or retrieve script content from an ADS.
sigmaWindowshigh2019-10-30Windows Process Creation Matching Mustang Panda Dropper Command-Line and winwsh.exe
Alerts on Windows process creation with temp-based wtaks/winwsh execution and script-launch command-line parameters.
sigmahigh2019-10-30Windows Image Load: Unsigned dbghelp.dll/dbgcore.dll Loaded by Suspicious Process
Alerts on unsigned loading of dbghelp.dll/dbgcore.dll, often associated with memory dump creation and credential-access workflows.
sigmaWindowshigh2019-10-27Windows Remote Thread Creation from Uncommon Parent Image
Alerts on remote thread creation on Windows when the source executable is rare, with exclusions for known benign image pairings.
sigmaWindowshigh2019-10-27Windows: Child Process Spawned with SYSTEM Integrity by LOCAL/NETWORK SERVICE Parent
Alert on Windows executions where a SYSTEM-integrity child is spawned by a LOCAL SERVICE or NETWORK SERVICE parent, excluding a specific rundll32 pattern.
sigmaWindowshigh2019-10-26Windows: sc.exe Service Configuration Changed by Medium-Integrity Users
Alerts on sc.exe runs from Medium-integrity users that include service config/binPath or failure command changes.
sigmaWindowshigh2019-10-26Windows Service Configuration Tampering by Medium-Integrity Processes
Alerts on medium-integrity processes running commands that target registry service configuration values for potential privilege escalation.
sigmaWindowshigh2019-10-26Windows getsystem via Meterpreter/Cobalt Strike when services.exe starts a likely privilege escalation command
Alerts when services.exe spawns cmd/%COMSPEC% commands writing to a named pipe consistent with getsystem behavior.
sigmaWindowshigh2019-10-26Windows Registry: Add-on DelegateExecute persistence via Narrator Feedback-Hub AppX key
Flags registry value deletions on a Narrator Feedback-Hub AppX DelegateExecute path used for persistence.
sigmaWindowshigh2019-10-25Windows: Registry CreateKey/Rename of HKLM\SYSTEM\CurrentControlSet\Control\MiniNt
Flags registry creation or renaming of the MiniNt key that can impair Windows event logging after reboot.
sigmaWindowshigh2019-10-25Linux auditd alerts on syslog daemon configuration file changes
Alerts when syslog daemon configuration files are changed on a Linux host via auditd PATH events.
sigmaLinuxhigh2019-10-25