Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Process in Suspicious Folder Initiating Network Connections to File Sharing Domains
Alerts on outbound connections to file sharing domains from Windows executables running out of suspicious temp/recycle/task paths.
sigmaWindowshigh2018-08-30Windows LSASS process access blocked by Attack Surface Reduction (Windows Defender event 1121)
Alerts on windefend EventID 1121 for blocked access to lsass.exe, excluding common benign process callers.
sigmaWindowshigh2018-08-26Windows Registry Run Key Set to Executable in Suspicious Folder
Flags new Windows Run key values pointing to executables in suspicious folders, excluding known update/Spotify patterns.
sigmaWindowshigh2018-08-25Windows Process Creation: PowerShell Command Execution Hidden in DLL Invocation
Flags DLL-invoking Windows binaries whose command lines include PowerShell execution strings.
sigmaWindowshigh2018-08-25Windows: .NET Reflection Attempt to Disable AMSI via amsiInitFailed
Alerts on Windows command lines referencing amsiInitFailed and .NET reflection patterns to disable AMSI scanning.
sigmaWindowshigh2018-08-17DNS TXT Answers Containing Command Execution Keywords (IEX, Invoke-Expression, cmd.exe)
Alerts on DNS TXT answers containing IEX/Invoke-Expression or cmd.exe strings indicative of execution-oriented payloads.
sigmaNetworkhigh2018-08-08PowerShell NTFS Alternate Data Stream Writes via set-content/add-content
Alerts on PowerShell Set/Add-Content operations that specify -Stream, indicating potential NTFS Alternate Data Stream writes.
sigmaWindowshigh2018-07-24Windows: SafetyKatz LSASS dump default file indicator (Temp\debug.bin)
Flags Windows file events with a target path ending in \Temp\debug.bin, consistent with SafetyKatz LSASS dump output.
sigmaWindowshigh2018-07-24Windows Registry Explorer Run Key Persistence Pointing to Suspicious Paths
Alerts on writes to the Explorer Run policy registry key with details pointing to suspicious filesystem paths.
sigmaWindowshigh2018-07-18Windows Registry Events: CMSTP Execution via cmmgr32.exe TargetObject
Flags registry events referencing \cmmgr32.exe, consistent with CMSTP-related execution behavior on Windows.
sigmaWindowshigh2018-07-16Windows CMSTP Process Spawning Child Process
Alerts on child processes spawned by Windows cmstp.exe, a common signal for CMSTP abuse.
sigmaWindowshigh2018-07-16Windows Process Access to cmlua.dll by CMSTP Connection Manager Profile Installer
Alerts on Windows process access events whose call trace includes cmlua.dll, indicating potential CMSTP-related execution.
sigmaWindowshigh2018-07-16Windows Process Creation: svchost.exe Spawns mshta.exe (LethalHTA)
Alerts on Windows instances where svchost.exe spawns mshta.exe, indicating potential LethalHTA execution.
sigmaWindowshigh2018-06-07Windows Security: Detects suspicious DC Sync via Event 4662 access to replication rights
Flags Windows EventID 4662 directory replication permission events matching DC Sync–related GUIDs and properties while excluding common service accounts.
sigmaWindowshigh2018-06-03Windows Registry Persistence via Image File Execution Options GlobalFlag and SilentProcessExit
Flags registry changes to IFEO GlobalFlag and SilentProcessExit keys that can enable stealthy persistence or process redirection.
sigmaWindowshigh2018-04-11Windows File Events: Known Offensive PowerShell Script File Creation
Alerts on creation of known offensive PowerShell/PowerShell module filenames on Windows.
sigmaWindowshigh2018-04-07Windows Process Creation: Suspicious Child Programs Spawned by mshta, PowerShell, wscript, rundll32
Alerts when mshta/PowerShell and similar script hosts spawn tasks, download/transfer, or utility tools on Windows.
sigmaWindowshigh2018-04-06Windows: Suspicious Process Spawning from Microsoft Office Applications
Alerts when Office apps spawn common execution tools or scripts from typical attacker staging paths on Windows.
sigmaWindowshigh2018-04-06Windows Proxy Activity Using Microsoft-WebDAV-MiniRedir GET User-Agent
Alerts on proxy HTTP GET requests using the Microsoft-WebDAV-MiniRedir/ User-Agent prefix associated with file download behavior.
sigmaWebhigh2018-04-06Windows Ping Hex IP Usage via Command Line
Flags ping.exe executions that pass a hex-encoded IPv4 address (0x????????) in the command line on Windows.
sigmaWindowshigh2018-03-23