Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Windows File Creation Time Altered to a Previous Year
Alerts on Windows events where a file’s creation time is altered to a different year, excluding common benign system/update tooling.
sigmalow2022-08-12Azure Audit Logs: End User Consent for Application (Non-Admin Consent)
Identifies end-user consent grants to applications in Azure AD audit logs.
sigmaCloudlow2022-07-28Azure AD Sign-in Success Without MFA (Single-Factor Authentication)
Alerts on successful Azure AD sign-ins where MFA was not required and only single-factor authentication was used.
sigmaCloudlow2022-07-27Windows curl.exe Process Creation
Alerts on execution of curl.exe on Windows, which may indicate remote downloads or web requests.
sigmalow2022-07-05Azure AD Sign-ins from Unknown Devices with Single-Factor Authentication
Alerts on successful Azure sign-ins using single-factor authentication with unknown or missing device identifiers from non-trusted contexts.
sigmaCloudlow2022-06-28Windows DNS Queries Containing ufile.io Domain
Alerts on Windows DNS lookups where the queried name contains ufile.io, indicating potential exfiltration-related activity.
sigmaWindowslow2022-06-23Windows PowerShell: Suspicious GPO Discovery via Get-GPO
Detects PowerShell script blocks using Get-GPO to enumerate domain Group Policy Objects.
sigmaWindowslow2022-06-04Windows JScript Compiler (jsc.exe) Process Execution
Identifies execution of jsc.exe (JScript Compiler) from Windows process creation logs.
sigmaWindowslow2022-05-02Zeek DNS: Detect NKN Seed Domain Queries
Alerts on Zeek DNS queries containing "seed" and ending with .nkn.org, a pattern consistent with NKN network activity.
sigmaNetworklow2022-04-21Windows File Access to Browser Credential Stores by Uncommon Processes
Detects suspicious process access to Firefox/Chromium credential store files on Windows, excluding common system and known benign paths.
sigmalow2022-04-09Windows Security: Outgoing Logon (LogonType 9) Using New Credentials (4624)
Flags Windows 4624 LogonType 9 events where new credentials are used for authentication.
sigmaWindowslow2022-04-06Windows PowerShell User Discovery via Current Username APIs
Alerts on PowerShell script blocks that retrieve the current username or user identity using common environment/.NET calls.
sigmaWindowslow2022-04-04Windows fsutil.exe Drive Enumeration via Process Execution
Flags fsutil.exe process launches with command lines referencing connected drive enumeration.
sigmaWindowslow2022-03-29Windows PowerShell: Suspicious Process Discovery Using Get-Process
Alerts when PowerShell script blocks contain Get-Process, indicating local process discovery activity.
sigmaWindowslow2022-03-17PowerShell Password Policy Discovery via Get-AdDefaultDomainPasswordPolicy (Windows)
Alerts when PowerShell calls Get-AdDefaultDomainPasswordPolicy to enumerate an AD domain’s default password policy.
sigmaWindowslow2022-03-17Windows PowerShell Active Directory Group Enumeration via Get-AdGroup Cmdlet
Flags PowerShell script blocks that call Get-ADGroup with -Filter to enumerate Active Directory groups.
sigmaWindowslow2022-03-17PowerShell: Active Directory computer enumeration via Get-AdComputer
Flags PowerShell script blocks using Get-ADComputer with enumeration-related parameters for AD computer discovery.
sigmaWindowslow2022-03-17Windows: Executable Creates Executable via File Creation Events
Flags .exe-to-.exe executable drops on Windows when a running executable creates another .exe, with exclusions for common system/update paths.
sigmalow2022-03-09Windows BITS Job Creation Triggered by PowerShell
Flags new BITS job creation on Windows when initiated by PowerShell (Event ID 3).
sigmaWindowslow2022-03-01Windows BITS job created by bitsadmin.exe (BITS Client EventID 3)
Alerts on new BITS job creation when bitsadmin.exe triggers it (BITS-Client EventID 3).
sigmaWindowslow2022-03-01