Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Webserver POST Uploads Java Web Shell Files in SAP NetViewer
Alerts on POST requests to /irj/ endpoints uploading Java extension files with octet-stream content type.
sigmahigh2025-05-14SAP NetViewer Webshell Command Execution via JSP cmd Parameter
Alerts on SAP NetViewer JSP requests likely used as webshells to execute system commands via cmd-style query parameters.
sigmahigh2025-05-14Suspicious cmd.exe execution from w3wp.exe tied to CentreStack portal.config (Windows process creation)
Alerts when w3wp.exe launches cmd.exe and its command line references \portal\portal.config, suggesting possible IIS app exploitation.
sigmahigh2025-04-17Windows Registry: MiniNt Key Added to Disable Security Event Logging on Reboot
Flags registry set activity that adds the MiniNt key, which stops Windows Event Log from writing events after a reboot.
sigmaWindowshigh2025-04-09Windows Process Creation: Disabling Security Logging via MiniNt Registry Key Set
Flags reg.exe or PowerShell commands that create/modify the MiniNt registry key to impair Windows event logging.
sigmaWindowshigh2025-04-09Windows Registry RunMRU Tampering with HTTP/HTTPS and Script Execution Indicators
Alerts on Windows RunMRU registry changes containing HTTP/HTTPS URLs plus captcha/automation or command execution indicators.
sigmaWindowshigh2025-03-25Windows Process Creation: Suspicious LNK Command-Line Whitespace Padding Beyond UI Limit
Alerts when explorer.exe launches a .lnk and the command line contains suspicious whitespace padding used to hide extended arguments.
sigmaWindowshigh2025-03-19Suspicious autorun registry modification via WMI wmic spawning reg.exe on Windows
Flags WMIC-driven reg.exe commands that add Run key autorun entries, especially when pointing to suspicious temp/user locations.
sigmaWindowshigh2025-02-17Windows curl.exe SOCKS Proxy and .onion Command-Line Execution
Alerts on Windows curl.exe being run with Tor SOCKS proxy URIs and .onion targets in the command line.
sigmahigh2025-02-11Windows Scheduled Task Creation Using System Process Names
Flags schtasks.exe /create commands whose arguments reference common Windows system process names.
sigmaWindowshigh2025-02-05Windows MMC Executes Files with RLO-Reversed Extensions in Process Command Line
Alerts when mmc.exe runs with command lines containing RLO-style reversed filename patterns ending in .msc.
sigmaWindowshigh2025-02-05Windows ConHost Spawning Suspicious Script and Command-Line Child Processes
Flags conhost.exe spawning command/scripting utilities like PowerShell, MSHTA, or regsvr32.exe.
sigmaWindowshigh2025-02-05Windows file creation of executable/script files in \Users\Public
Alerts on Windows file creation in \Users\Public\ with potentially malicious script/binary extensions.
sigmaWindowshigh2025-01-23Linux: Shell spawned by rsync without -e flag in command line
Flags rsync/rsyncd spawning a shell when rsync lacks the expected " -e " command-line flag.
sigmaLinuxhigh2025-01-18Windows Registry EventLog ChannelAccess SDDL Tampering Detection
Detects registry changes to Windows Event Log ChannelAccess SDDL, which can limit event log visibility or control.
sigmaWindowshigh2025-01-16M365 Audit: Successful Intune Company Portal login via Cmsi
Flags successful Company Portal (Intune) logins via Cmsi audit events that may indicate Conditional Access bypass attempts.
sigmaCloudhigh2025-01-08Windows Application Error 1000 with lsass.exe and WLDAP32.dll Indicating LDAP Nightmare Attempt (CVE-2024-49113)
Alerts on Windows Application Error (EventID 1000) showing lsass.exe crashing in WLDAP32.dll—potential CVE-2024-49113 exploitation attempt.
sigmahigh2025-01-08Windows Process Creation: Execution of vbc.exe Spawned from more.com
Alerts when more.com starts vbc.exe on Windows, matching a known stealer execution pattern.
sigmahigh2024-12-19Windows File Creation to Roaming AppData DataLogs.conf and RAT-Client Names
Alerts on creation of specific RAT client config files under AppData\Roaming on Windows.
sigmahigh2024-12-19Windows Process Creation: Suspicious cmd.exe Launch with Encoded PowerShell from Cleo Suite
Alerts on cmd.exe launching PowerShell encoded commands from Cleo javaw.exe components with .Download.
sigmahigh2024-12-09