Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Linux auditd: Monitor changes to /etc/audit, /etc/libaudit.conf, and /etc/audisp files
Flags modifications to Linux auditd configuration files that can weaken host auditing.
sigmaLinuxhigh2019-10-25Windows Process Creation: WSReset.exe Used with Non-CONHOST Child Process
Alerts when wsreset.exe spawns a process other than conhost.exe, a potential UAC-bypass precursor.
sigmaWindowshigh2019-10-24Windows: Detect Fodhelper.exe spawned processes indicative of UAC bypass
Flags process creation where the parent is Fodhelper.exe, a common UAC bypass execution pattern on Windows.
sigmaWindowshigh2019-10-24Windows: Command-line execution of cmstp.exe with INF install/silent/autobind flags (UAC bypass pattern)
Alerts when cmstp.exe is launched with INF installation and silent/auto options indicating a UAC-bypass style behavior.
sigmaWindowshigh2019-10-24Windows Process Creation: LSASS .dmp/related Dump Keywords in Command Line
Alerts on Windows command lines containing LSASS dump keywords and .dmp/MDMP/zip/rar variants.
sigmaWindowshigh2019-10-24Windows Mshta.exe Launching JavaScript via Command Line
Detects Mshta.exe executions where the command line includes "javascript".
sigmaWindowshigh2019-10-24Windows: Suspicious subprocess execution from Hwp.exe spawning gbb.exe
Alerts when Hwp.exe launches gbb.exe, a suspicious child process pattern on Windows.
sigmaWindowshigh2019-10-24Windows Execution of dnscat2 and iodine DNS Exfiltration/Tunneling Tools
Flags Windows execution of DNS tunneling/exfiltration tools identified by iodine.exe or dnscat2 in process creation events.
sigmaWindowshigh2019-10-24Windows Boot Configuration Tampering via bcdedit.exe
Flags bcdedit.exe commands that set boot status policy to ignore failures and disable recovery (recoveryenabled=no).
sigmaWindowshigh2019-10-24Windows at.exe Interactive Job via Process Creation
Alerts on at.exe process launches that include 'interactive' in the command line on Windows.
sigmaWindowshigh2019-10-24Windows Security 4673: Failed LsaRegisterLogonProcess Handle Registration
Alerts on failed attempts to call LsaRegisterLogonProcess() in Windows Security (Event 4673), tied to the SeTcbPrivilege requirement.
sigmaWindowshigh2019-10-24Windows Security 4611: Rubeus-Indicative New Trusted Logon Process Registration
Alerts on Windows Security Event 4611 registering a new trusted logon process named 'User32LogonProcesss'.
sigmaWindowshigh2019-10-24Linux: Detect Modification of /etc/ld.so.preload for Shared Object Injection
Flags auditd activity where /etc/ld.so.preload is modified, indicating potential shared object injection.
sigmaLinuxhigh2019-10-24Windows: Sysmon filter driver unloaded using fltMC.exe
Identifies fltMC.exe commands attempting to unload the Sysmon filter driver via “unload sysmon”.
sigmaWindowshigh2019-10-23Windows Shadow Copy Deletion via PowerShell, WMIC, vssadmin, diskshadow, or wbadmin
Flags Windows commands that use shadow-copy management utilities with deletion or shadowstorage removal parameters.
sigmaWindowshigh2019-10-22Windows reg.exe Registry Hive Dumping for SAM, SYSTEM, and SECURITY
Flags reg.exe command lines exporting or saving HKLM registry hives tied to SAM, SYSTEM, and SECURITY.
sigmaWindowshigh2019-10-22Windows Process Execution Matching SILENTTRINITY Stager Metadata (st2stager)
Flags Windows process creation events containing "st2stager" in PE metadata, indicating SILENTTRINITY stager activity.
sigmaWindowshigh2019-10-22Windows Process Creation: Detect Mimikatz Tool and Module Command-Line Usage
Flags Windows processes whose command lines contain Mimikatz names and credential-dumping module/function arguments.
sigmaWindowshigh2019-10-22Windows: Detect esentutl.exe Copying Sensitive Credential Files via VSS
Alerts on esentutl.exe VSS usage and command lines referencing SAM/SECURITY/SYSTEM or ntds.dit copy targets.
sigmaWindowshigh2019-10-22Windows Volume Shadow Copy Symlink Creation Using mklink
Flags Windows mklink commands that reference HarddiskVolumeShadowCopy to create symlinks.
sigmaWindowshigh2019-10-22