Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
Windows Process Creation: SecurityXploded PasswordDump.exe Execution
Alerts on Windows executions of SecurityXploded PasswordDump.exe based on process metadata and filename.
sigmaWindowscritical2018-12-19Windows Process Creation: Rubeus HackTool Execution Indicators
Flags Windows process executions of Rubeus.exe when command lines include Kerberos attack-related actions.
sigmaWindowscritical2018-12-19Windows Service Control Manager: WerFaultSvc Installed via Service Creation (Event ID 7045)
Alerts on Windows Event 7045 service creation for "WerFaultSvc" as an indicator of dropper-style persistence.
sigmacritical2018-11-23Windows Process Creation—CommandLine Indicators for APT29 2018 Phishing Campaign
Alerts on Windows command-line substrings seen in the 2018 APT29 phishing campaign indicators.
sigmacritical2018-11-20Windows File Events: Detect ds7002*.lnk, .pdf, and .zip Indicators
Flags Windows file events with target filenames containing ds7002.lnk, ds7002.pdf, or ds7002.zip.
sigmacritical2018-11-20Antivirus Credential Dumping Signature Match (Password Dumpers/Stealers)
Triggers on AV signatures matching PWS* or known credential-dumping tool strings indicating potential password theft activity.
sigmacritical2018-09-09Antivirus signature match for exploitation framework indicators
Alerts when AV signature names contain indicators tied to exploitation frameworks and related backdoors.
sigmacritical2018-09-09Windows process creation: svchost.exe launched by sllauncher.exe for DLL side-loading
Flags AppData\Roaming-launched svchost.exe instances spawned by sllauncher.exe with -k, matching DLL side-loading execution behavior.
sigmacritical2018-09-03Web server access to WebLogic keystore JavaScript webshell URLs
Flags web requests attempting to access JavaScript content within a WebLogic keystore path.
sigmacritical2018-07-22Cobalt Strike-style DNS Beaconing Queries (DNS)
Flags DNS queries with Cobalt Strike-style stage subdomain patterns used for covert beaconing.
sigmaNetworkcritical2018-05-10Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Alerts on Windows service installation events for persistence-related scheduled services named SC Scheduled Scan or UpdatMachine.
sigmacritical2018-03-23Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Alerts on Windows scheduled task creation events (4698) for task names "SC Scheduled Scan" and "UpdatMachine".
sigmacritical2018-03-23Windows Registry Persistence via UMe/UT Run Keys
Alerts on Windows registry changes to UMe/UT run key subpaths associated with persistence.
sigmacritical2018-03-23Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Alerts when scheduled task and Service.exe processes launch autoit3.exe that runs nslookup TXT queries from a temp staging path.
sigmacritical2018-03-23Windows Registry Image File Execution Options Debugger Backdoor (sethc.exe/utilman.exe/osk.exe)
Alerts on registry Debugger hijacks for Windows login/accessibility binaries using Image File Execution Options.
sigmaWindowscritical2018-03-15Windows Backdoor Execution via Sticky Keys and Login-Screen Accessibility Tools
Flags winlogon.exe spawning command/script tools referencing login-screen accessibility binaries (sethc.exe, utilman.exe, osk.exe, etc.).
sigmaWindowscritical2018-03-15WinWord spawning MicroScMgmt.exe indicative of CVE-2015-1641 exploitation on Windows
Alerts when Winword.exe starts MicroScMgmt.exe, matching a known CVE-2015-1641 exploitation behavior.
sigmacritical2018-02-22Windows File Creation: QuarksPwDump Credential Dump (.dmp) in Temp\SAM-*
Flags creation of QuarksPwDump .dmp dump files in Temp with a SAM-* filename pattern.
sigmaWindowscritical2018-02-10Windows Process Creation: svchost Running NavShExt.dll Deletion/Setting Commands
Alerts on svchost.exe process commands referencing cached NavShExt.dll deletion and execution markers consistent with Elise backdoor activity.
sigmacritical2018-01-31Windows Process Creation: EQNEDT32.EXE Used as CVE-2017-11882 Exploit Dropper Parent
Flags Windows process creation where EQNEDT32.EXE is the parent, matching CVE-2017-11882 exploitation dropper behavior.
sigmacritical2017-11-23