Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
528 rules
Windows Process Creation: PowerShell COM CLSID Download Cradles
Alerts on PowerShell command lines using GetTypeFromCLSID with selected CLSIDs that may be used to download files via COM.
sigmaWindowsmedium2022-12-25PowerShell ScriptBlock COM CLSID GetTypeFromCLSID Download Cradle Indicators
Alerts on PowerShell script blocks using GetTypeFromCLSID with specific CLSIDs indicative of COM-based download cradles.
sigmaWindowsmedium2022-12-25Windows PowerShell: In-Memory Assembly Loading via Reflection.Assembly
Flags PowerShell script blocks that reference [Reflection.Assembly]::load for potential in-memory assembly loading.
sigmaWindowsmedium2022-12-25Windows Process Execution: Suspicious AgentExecutor.exe PowerShell Launch with ExecutionPolicy Bypass
Detects AgentExecutor.exe command lines that trigger PowerShell script execution, including remediations and potentially bypassed ExecutionPolicy.
sigmaWindowshigh2022-12-24Windows AgentExecutor.exe PowerShell Execution (ExecutionPolicy Bypass) Process Creation
Alerts on AgentExecutor.exe launches that pass -powershell/-remediationScript to run PowerShell (including bypass execution policy).
sigmaWindowsmedium2022-12-24PowerShell FromBase64String Decoding of Base64 Gzip Content in Process Creation on Windows
Windows process command lines using PowerShell FromBase64String with MemoryStream and Gzip-like Base64 markers (H4sI) are flagged.
sigmaWindowsmedium2022-12-23Windows PowerShell Execution of AADInternals Cmdlets (process creation)
Flags PowerShell processes running AADInternals “-AADInt” cmdlets, indicating potential Azure AD/Office 365 administration or abuse.
sigmaWindowshigh2022-12-23Suspicious X509Enrollment usage in Windows PowerShell scripts
Alerts on PowerShell script blocks containing X509Enrollment.CBinaryConverter and a specific enrollment GUID.
sigmaWindowsmedium2022-12-23PowerShell: FromBase64String Decoding of Gzip (H4sI) into MemoryStream
Identifies PowerShell script blocks that base64-decode and Gzip-unpack embedded content using in-memory streams.
sigmaWindowsmedium2022-12-23Windows PowerShell Script Block Logging: AADInternals Cmdlets (Add-AADInt to Update-AADInt) Execution
Flags PowerShell script block execution that contains AADInternals cmdlet names (AADInt), indicating potential admin or abuse activity.
sigmaWindowshigh2022-12-23Windows: Explorer opened from cmd.exe/powershell using shell:MyComputerFolder shortcut
Flags explorer.exe opened for My Computer via shell:mycomputerfolder when started by cmd or PowerShell.
sigmaWindowshigh2022-12-22Webserver: OWASSRF exploitation attempt via OWA to PowerShell backend
Flags webserver POSTs returning 200 that request both /owa/mastermailbox and /powershell, consistent with OWASSRF exploitation attempts.
sigmacritical2022-12-22Detect OWASSRF Webserver Exploitation Pattern Targeting PowerShell Backend
Alerts on successful POST requests to OWA URLs containing PowerShell backend indicators and Exchange-like probe user agents.
sigmahigh2022-12-22Detects OWASSRF Proxy Exploitation Attempt via OWA to PowerShell Backend
Identifies proxy POSTs that return 200 and request both /owa/mastermailbox and /powershell, indicating potential OWASSRF exploitation.
sigmacritical2022-12-22Potential OWASSRF Exploitation via OWA Proxy Requests (HTTP 200) - Exchange
Alerts on 200-status proxy POSTs targeting OWA-to-PowerShell backend paths with encoded user info markers.
sigmahigh2022-12-22Windows Registry Set Detection of Suspicious Environment Variable Commands
Flags Windows registry environment variable registrations that include PowerShell and base64-encoded command fragments.
sigmaWindowshigh2022-12-20Windows PowerShell nslookup DNS TXT Download Cradle
Identifies PowerShell launching an nslookup-based cradle that queries TXT records with HTTP-related nslookup parameters.
sigmaWindowsmedium2022-12-10Windows: Elevated PowerShell or CMD Spawned from Uncommon Parent Location
Alerts on elevated PowerShell/CMD executions whose parent process comes from uncommon Windows locations, indicating likely privilege escalation.
sigmaWindowsmedium2022-12-05PowerShell Get-ADUser User Discovery and Data Export via File Output
Detects PowerShell Get-ADUser-based user enumeration combined with exporting results to files or output streams.
sigmaWindowsmedium2022-11-17PowerShell Get-ADComputer Cmdlet Used for Computer Discovery and File Export
Flags PowerShell Get-ADComputer wildcard enumeration followed by writing exported computer data to a file.
sigmaWindowsmedium2022-11-17