Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
sigmaWindowshigh2019-04-15Linux Command Lines Creating Symlink to /etc/passwd
Alerts on Linux command lines attempting to create symlinks to /etc/passwd via ln -s/ln -f patterns.
sigmaLinuxhigh2019-04-05Windows GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Writes (Security 5136/5145)
Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.
sigmaWindowshigh2019-04-03Windows Security 4661 Detects Privileged AD User/Group SID Enumeration via SAM
Identifies SAM_USER/SAM_GROUP access events (4661) aimed at privileged SIDs or names containing 'admin' while ignoring computer accounts.
sigmaWindowshigh2019-04-03Windows Security 5136: Modify AD ACL for DCSync Extended Right via ntSecurityDescriptor
Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.
sigmaWindowshigh2019-04-03Windows Suspicious EXE in User Directory Launched by Microsoft Office Applications
Alert on Office spawning a .exe from C:\users\ (except when the child is Teams.exe).
sigmaWindowshigh2019-04-02Linux Suspicious Reverse Shell Command-Line Execution Patterns
Alerts on Linux command lines containing reverse-shell-style strings such as /dev/tcp redirections, netcat pipes, and socket connect patterns.
sigmaLinuxhigh2019-04-02Windows process creation matching EmpireMonkey-style jscript execution from Temp Errors.bat
Alerts on Windows executions that combine /e:jscript with a \Local\Temp\Errors.bat batch path.
sigmahigh2019-04-02Windows Security Event 5136: Suspicious LDAP attribute display names used
Alerts on Event 5136 containing specific LDAP display names indicative of LDAP-based data exchange.
sigmaWindowshigh2019-03-24Windows ETW Trace Evasion via Clearing/Disabling Logs or Providers
Identifies command-line attempts to clear/disable ETW traces or remove/modify ETW providers on Windows.
sigmaWindowshigh2019-03-22Microsoft BITS Proxy Activity to Uncommon Top-Level Domains
Flags Microsoft BITS-initiated proxy requests to domains using uncommon TLDs.
sigmaWebhigh2019-03-07Windows: PowerShell-triggered HTA retrieval and execution with registry and process disruption
Alerts on Windows process creation where PowerShell uses mshta over HTTP and includes .hta, registry query, and cmd.exe termination.
sigmahigh2019-02-24Windows mshta.exe Execution Using Non-HTA File Extensions
Alerts on mshta.exe launched with command-line indicators for suspicious non-HTA file types and VBScript.
sigmaWindowshigh2019-02-22Windows: RDP Session Startup Folder Backdoor via tsclient Share Targeting Startup Path
Flags mstsc.exe activity writing to the Windows Startup folder, indicating potential RDP session backdoor placement.
sigmaWindowshigh2019-02-21Windows svchost RDP via Reverse SSH Loopback Tunnel to 127.0.0.0/8:3389
Flags svchost.exe opening RDP (TCP 3389) connections to loopback, consistent with tunneled reverse access behavior.
sigmaWindowshigh2019-02-16Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Flags Windows EventID 5156 where svchost RDP (3389) traffic targets loopback addresses, suggesting tunneled local RDP usage.
sigmaWindowshigh2019-02-16Windows Registry Persistence Attempt Using AppDataLow Ursnif-Related Path
Alerts on Windows registry key additions matching a Ursnif-associated TargetObject path.
sigmahigh2019-02-13Windows: Alert on suspicious parent process spawning csc.exe
Flags csc.exe execution when spawned by script/document hosts or PowerShell using encoded content, excluding common benign parent contexts.
sigmaWindowshigh2019-02-11Windows Process Creation: Suspicious calc.exe Command-Line Usage Outside System Locations
Alerts on suspicious calc.exe launches via command-line parameters or execution from non-standard Windows directories.
sigmaWindowshigh2019-02-09Windows Process Creation: Suspicious GUP.exe Execution from Non-Notepad++ Directories
Alerts on GUP.exe executions from unexpected directories on Windows, excluding known Notepad++ updater paths.
sigmaWindowshigh2019-02-06