Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Remote Thread Creation via CACTUSTORCH Using Script/Office/Rundll Host Images
Alerts on SysWOW64 remote thread creation initiated by script host or Office binaries consistent with CACTUSTORCH behavior.
sigmaWindowshigh2019-02-01Chafer malware C2 URLs with /asp.asp?ui= pattern over HTTP proxy
Flags proxy HTTP requests containing the C2 URI pattern /asp.asp?ui= associated with Chafer behavior.
sigmahigh2019-01-31Windows netsh.exe Used to Create RDP (3389) Port Forwarding
Flags netsh.exe executions that appear to set up RDP (3389) port forwarding.
sigmaWindowshigh2019-01-29Windows RDP Logon Using Localhost IP Address
Alerts on successful Windows logons (EventID 4624, LogonType 10) originating from localhost IPs.
sigmaWindowshigh2019-01-28Windows Registry: New Security Support Provider (SSP) added to LSA configuration
Alerts when a new SSP is added to LSA Security Packages in the Windows registry, excluding msiexec-driven changes.
sigmaWindowshigh2019-01-18Windows Suspicious Child Processes Spawned by Web Server Executables
Alerts when web server processes (e.g., nginx/httpd/caddy/php/tomcat) spawn suspicious Windows command/scripting executables.
sigmaWindowshigh2019-01-16Windows Process Execution From Uncommon or Sensitive Directories
Alerts on process executions from uncommon/sensitive Windows directories, excluding specific IBM and Citrix updater paths.
sigmaWindowshigh2019-01-16Windows Process Creation: Suspicious PowerShell Argument Obfuscation via Truncated Substrings
Alerts on PowerShell executions where the command line contains suspicious truncated parameter substrings (e.g., windowstyle, NoProfile, encoded/exec policy, bypass).
sigmaWindowshigh2019-01-16Windows Process Creation: PowerShell Command Lines with Hidden Base64-Encoded Keywords
Alerts on PowerShell launching with 'hidden' and embedded base64-like strings in the command line.
sigmaWindowshigh2019-01-16Windows Process Creation: Suspicious Children Spawned by mshta.exe
Flags mshta.exe spawning command, script, or utility processes commonly abused for executing malicious HTA payloads.
sigmaWindowshigh2019-01-16Windows Cmdkey.EXE Cached Credential Reconnaissance
Alerts on cmdkey.exe running with -l to enumerate cached credentials on a Windows host.
sigmaWindowshigh2019-01-16Windows userinit.exe Spawns Uncommon Child Processes
Alerts when userinit.exe starts an unexpected child process during logon, suggesting potential persistence via modified logon behavior.
sigmaWindowshigh2019-01-12Windows Command Line Logon Script Persistence via UserInitMprLogonScript
Alerts when a Windows process command line references UserInitMprLogonScript, a potential logon-script persistence indicator.
sigmaWindowshigh2019-01-12Windows Process Creation: Outlook EnableUnsafeClientMailRules Security Setting Enabled
Flags Windows process command lines that reference Outlook’s EnableUnsafeClientMailRules security setting.
sigmaWindowshigh2018-12-27Windows Remote Thread Injection Indicators via Process StartAddress Suffixes
Flags Windows CreateRemoteThread events with StartAddress suffixes 0B80, 0C7C, or 0C88.
sigmaWindowshigh2018-11-30Windows PowerShell Base64-encoded shellcode in ScriptBlockText
Flags PowerShell script blocks containing Base64 strings matching known shellcode markers.
sigmaWindowshigh2018-11-17Windows ProcDump Command Lines Targeting LSASS Memory Dumps
Identifies suspicious ProcDump usage with dump flags and LSASS-related markers to indicate potential credential harvesting.
sigmaWindowshigh2018-10-30Antivirus Web Shell Signature Matches Across ASP, JSP, PHP, Perl, and VBS
Alerts on AV signatures indicating web shells/backdoors (ASP/JSP/PHP/Perl/VBS/Webshell) to support fast investigation of persistence.
sigmahigh2018-09-09Antivirus alerts for suspicious file paths and web/script file extensions
Alerts on AV hits involving suspicious file locations and web/script-related extensions.
sigmahigh2018-09-09Windows PowerShell Suspicious Encoded Command-Line Execution
Alerts on PowerShell launched with encoded-command switches and embedded encoded content patterns in the command line.
sigmaWindowshigh2018-09-03