Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Security: SeEnableDelegationPrivilege Enabled via AD User Right (Event 4704)
Alerts when Event ID 4704 assigns SeEnableDelegationPrivilege, enabling control over other AD user objects.
sigmaWindowshigh2017-07-30Suspicious Malformed User-Agent Strings in Proxy Logs
Flags proxy requests whose User-Agent headers are malformed or match suspicious automation/tooling patterns, excluding known Adobe/Acrobat traffic.
sigmaWebhigh2017-07-08Suspicious Malware User-Agent Strings in Proxy Logs
Alerts on proxy traffic with user-agent values and substrings commonly seen in malware communications.
sigmaWebhigh2017-07-08Proxy logs: Detect suspicious hack tool user agents from known scanning and SQLi tools
Alerts on proxy requests with User-Agent values commonly used by scanners and hack tools, indicating automated probing or exploitation attempts.
sigmaWebhigh2017-07-08Proxy logs: suspicious exploit framework User-Agent strings
High-severity match on proxy User-Agent strings commonly seen in exploit/pentest frameworks.
sigmaWebhigh2017-07-08Windows Process Creation: Suspicious Execution of PlugX DLL Side-Loading Utilities from Uncommon Paths
Alerts on execution of PlugX-related helper binaries from atypical paths, excluding common legitimate directories.
sigmahigh2017-06-12Windows Process Creation: Fireball Archer installs via rundll32.exe and InstallArcherSvc
Flags rundll32.exe executions referencing InstallArcherSvc in the process command line on Windows.
sigmahigh2017-06-03Windows Security: Detects RULER workstation using NTLM and login events (Event IDs 4776, 4624/4625)
Alerts when RULER-labeled Windows Security events show NTLM auth (4776) plus 4624/4625 logons.
sigmaWindowshigh2017-05-31Windows Registry: DHCP Server Callout DLL and Enable Parameters Installation
Alerts on registry changes enabling and configuring DHCP Server callout DLLs via CalloutDlls and CalloutEnabled.
sigmaWindowshigh2017-05-15Windows ETW: Kernel-General resets registry hive access bits in temp hive paths
Detects ETW EventID 16 when access bits are reset for Temp \SAM or \SECURITY hives.
sigmaWindowshigh2017-05-15Windows DHCP Server Error: Callout DLL Failed to Load
Flags DHCP Server events showing failure to load a configured Callout DLL (Event IDs 1031/1032/1034).
sigmaWindowshigh2017-05-15Windows DHCP Server Loaded Callout DLL via Registry
Flags DHCP Server events where a registry-specified callout DLL is loaded (Event ID 1033), indicating potential persistence or execution.
sigmaWindowshigh2017-05-15Windows Error Reporting: MsMpEng.exe Crash with mpengine.dll
Alerts on WER EventID 1001 crashes where MsMpEng.exe and mpengine.dll appear in the event data.
sigmaWindowshigh2017-05-09Windows Application Error: MsMpEng.exe Crash Involving mpengine.dll
Alerts on Windows Application Error EventID 1000 indicating a crash involving MsMpEng.exe and mpengine.dll.
sigmaWindowshigh2017-05-09Windows DNS ServerLevelPluginDll Registry Installation
Detects registry changes setting DNS ServerLevelPluginDll, which can enable malicious DNS plugin DLL loading after restart.
sigmaWindowshigh2017-05-08Windows: Detect dnscmd.exe setting ServerLevelPluginDll to install DNS plugin DLL
Flags dnscmd.exe DNS configuration that sets ServerLevelPluginDll, indicating potential malicious DNS server code injection.
sigmaWindowshigh2017-05-08Windows DNS Server error when loading ServerLevelPlugin DLL fails
Flags Windows DNS Server errors where the ServerLevelPluginDLL plugin DLL fails to load.
sigmaWindowshigh2017-05-08Windows Rundll32 DLL Load via control.exe spawning
Alerts on control.exe spawning rundll32.exe to load Shell32.dll via DLL invocation patterns.
sigmaWindowshigh2017-04-15Firewall Alerts for C2 IP Traffic to 69.42.98.86 and 89.185.234.145
Alerts when firewall traffic involves the two specified IPs associated with presumed C2 communication.
sigmahigh2017-04-15Windows Security: AD user/computer backdoor via msDS-AllowedToDelegateTo and delegation attributes
Alerts on AD delegation-related attribute changes that may create credentialless account control paths.
sigmaWindowshigh2017-04-13