Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Service Control Manager flags smbexec.py-style service installation via suspicious ImagePath
Flags suspicious Windows service installations matching a specific service name and BAT/delete command patterns in Event 7045.
sigmaWindowshigh2018-03-20Windows Security: Registry NetNTLM Downgrade Configuration Changes
Alerts on Windows registry changes that weaken NetNTLM/NTLM security settings via LSA compatibility and restriction values.
sigmaWindowshigh2018-03-20Windows Process Creation: taskmgr.exe launched in LOCAL_SYSTEM context
Flags taskmgr.exe process creation when initiated under a LOCAL_SYSTEM-equivalent user context string.
sigmaWindowshigh2018-03-18Windows Suspicious RDP Session Redirect via tscon.exe /dest:rdp-tcp#
Alerts on Windows process executions using tscon.exe-style RDP redirection to an "rdp-tcp#" destination.
sigmaWindowshigh2018-03-17Windows: Detect tscon.exe launched under SYSTEM context
Alerts on tscon.exe starting under a SYSTEM-associated user context based on Windows process creation logs.
sigmaWindowshigh2018-03-17Windows WMI Persistence via wbemcons.dll Loaded by WmiPrvSE.exe
Identifies WmiPrvSE.exe loading wbemcons.dll, a behavior consistent with WMI command line event consumer persistence on Windows.
sigmaWindowshigh2018-03-07Windows WMI Persistence: Script Event Consumer File Writes (scrcons.exe)
Flags file writes performed by scrcons.exe, indicating potential WMI script event consumer persistence activity.
sigmaWindowshigh2018-03-07Windows Scheduled Task Creation via PowerShell Using schtasks.exe with ONLOGON/DAILY/ONIDLE/HOURLY
Flags PowerShell-launched schtasks.exe /Create commands matching default PowerSploit/Empire scheduled task persistence behavior.
sigmaWindowshigh2018-03-06Windows rundll32 Trojan Loader Execution via Local AppData and .dat Parameters
Flags rundll32.exe launched with AppData/local .dat and .dll patterns consistent with Trojan loader behavior.
sigmahigh2018-03-01Linux syslog: Detect suspicious BIND/named error messages
Alerts on Linux syslog messages with BIND named fatal or denied DNS error strings.
sigmaLinuxhigh2018-02-20Windows Successful Logon Type 9 (NewCredentials) Matching Overpass-the-Hash
Flags successful Windows NewCredentials (LogonType 9) logons using seclogo with Negotiate, consistent with Overpass-the-Hash behavior.
sigmaWindowshigh2018-02-12Windows System Binary Execution From Unusual Location (Process Creation)
Alerts when common Windows system binaries run from an uncommon directory rather than standard system locations.
sigmaWindowshigh2017-11-27Web/SQL Application Logs: SQL Error Strings Indicative of Injection Probing
Flags SQL error log messages with injection-probing syntax/quoting/UNION mismatch keywords.
sigmahigh2017-11-27Windows File Events: java.exe in AppData\Roaming\Oracle\bin Path with .exe and .vbs Artifacts
Alerts on Windows file events for suspicious java*.exe placement in AppData\Roaming\Oracle\bin and .vbs files containing "Retrive".
sigmaWindowshigh2017-11-10Windows Process Creation: javaw.exe Command Line Indicates Adwind/JRAT Roaming Oracle Path
Flags command-line patterns indicating javaw.exe execution from AppData\Roaming\Oracle with java/.exe markers.
sigmahigh2017-11-10Proxy Web Requests for Flash Player Installer from Unofficial Locations
Flags proxy downloads for Flash Player installer paths when the request host is not ending in .adobe.com.
sigmaWebhigh2017-10-25Windows: Detect Renamed ps.exe Executing netstat via cmd /c
Alerts on Windows executions of renamed PsTool-like ps.exe that include accept-eula and netstat via cmd.exe.
sigmahigh2017-10-22Linux JexBoss Suspicious Bash Command Launch with /dev/tcp
Flags Linux executions containing bash -c /bin/bash paired with /dev/tcp/ indicative of a reverse-shell command sequence.
sigmaLinuxhigh2017-08-24Linux Suspicious Shell Command Lines for Exploit/Payload Delivery
Detects Linux command-line strings matching wget/piping, payload staging, permission changes, and socat/HTTP server execution patterns.
sigmaLinuxhigh2017-08-21Windows Security: Account Encryption/Preauth/Delegation Flags Weakened in User Account Changes
Flags Windows Event ID 4738 user account changes that enable weaker encryption or related pre-auth behavior.
sigmaWindowshigh2017-07-30