Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows: Detect sc.exe Service Config binPath Changes to Suspicious Commands/Paths
Alerts when sc.exe updates a service binPath to point at suspicious commands or commonly abused directories.
sigmaWindowshigh2019-10-21Suspicious Crypto Miner User Agents in Proxy Logs
Flags proxy requests with User-Agent prefixes tied to XMRig or CCMiner crypto miners.
sigmaWebhigh2019-10-21Linux Sudo Privilege Escalation Attempt Matching CVE-2019-14287 Command-Line Pattern
Alerts on Linux process command lines containing ' -u#' indicative of sudo CVE-2019-14287 exploitation attempts.
sigmahigh2019-10-15Windows OpenWith.exe Launches Another Binary via /c
Flags Windows OpenWith.exe executions that include '/c', indicating it launched another binary.
sigmaWindowshigh2019-10-12Windows Devtoolslauncher.exe LaunchForDeploy Executes a Specified Binary
Alerts when devtoolslauncher.exe runs with LaunchForDeploy, indicating it may launch another binary on Windows.
sigmaWindowshigh2019-10-12PowerShell ScriptBlock uses rundll32 with shell32.dll and obfuscated invoke/comspec/iex
Flags PowerShell script blocks containing rundll32/shell32.dll execution strings alongside invoke/iex/comspec patterns.
sigmaWindowshigh2019-10-08PowerShell module: Obfuscated Invoke via rundll32/shell32.dll comspec iex patterns
Flags PowerShell module payloads containing obfuscated rundll32 shell32.dll shellexec_rundll invocation patterns.
sigmaWindowshigh2019-10-08Windows Suspicious Run Key Created from Downloads or Outlook/IE Temporary Folders
Alerts on registry Run key writes originating from Downloads or temporary Outlook/IE directories on Windows.
sigmaWindowshigh2019-10-01Suspicious Windows Program Execution from Outlook Temporary Internet Files Folder
Alerts on process executions whose image path points to Outlook temporary files (Content.Outlook).
sigmaWindowshigh2019-10-01Windows Formbook-style process execution deleting dropped payloads from AppData Temp via cmd
Flags Windows process creation where an .exe runs deletion commands to remove dropper artifacts from AppData Temp/Desktop.
sigmahigh2019-09-30Windows Process Creation: Emotet-like Command-Line Patterns
Alerts on Windows process executions with command-line indicators consistent with Emotet-like staging and encoded payload usage.
sigmahigh2019-09-30Windows Process Activity Clearing or Modifying Event Logs via Wevtutil, PowerShell, or WMI
Flags suspicious Windows process command lines that clear or reconfigure Event Logs using wevtutil, PowerShell, or WMI, with an msiexec exception.
sigmaWindowshigh2019-09-26Windows fsutil.exe Suspicious USN Journal and File Zeroing Parameters
Alerts when fsutil.exe is run with USN journal deletion/creation or setZeroData-style file zeroing commands.
sigmaWindowshigh2019-09-26Windows Registry: Enable WDigest UseLogonCredential (Use clear-text logon credential setting)
Flags registry writes that enable WDigest UseLogonCredential, turning on potential clear-text credential storage.
sigmaWindowshigh2019-09-12Windows: WinRM inbound network connections to ports 5985/5986 for PowerShell remoting
Alerts on WinRM inbound connections (ports 5985/5986) consistent with remote PowerShell remoting activity.
sigmaWindowshigh2019-09-12Windows Suspicious Debugger Registration via Image File Execution Options
Alerts on Windows attempts to set Image File Execution Options debuggers for logon screen binaries via command-line arguments.
sigmaWindowshigh2019-09-06Windows Registry: Modification of WDigest IsCredGuardEnabled to Disable Credential Guard
Alerts on Windows registry changes to WDigest\IsCredGuardEnabled that may disable Credential Guard.
sigmaWindowshigh2019-08-25PowerShell FromBase64String CommandLine Base64 Encoded Usage (Windows)
Flags PowerShell command lines containing FromBase64String along with base64-encoded UTF-16 marker patterns.
sigmaWindowshigh2019-08-24Windows PowerShell Base64 Command Line Executing IEX
Identifies Windows PowerShell processes with Base64-encoded command-line content that contains an IEX execution pattern.
sigmaWindowshigh2019-08-23Windows Security: SysKey-related LSA Registry Key Access (4656/4663)
Alerts on access to LSA registry keys used to compute SysKey based on Windows Security handle and registry object events.
sigmaWindowshigh2019-08-12