Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
PowerShell Credential Prompt via PromptForCredential
Flags PowerShell scripts that reference "PromptForCredential", indicating credential prompt behavior in Script Block Logging.
sigmaWindowshigh2017-04-09Linux Command-Line Indicators of Equation Group Tooling
Flags execution of known suspicious Linux shell command patterns tied to Equation Group-style scripting and tooling.
sigmaLinuxhigh2017-04-09Windows CScript and csvde Command-Line Execution Patterns Suggesting Cloud Hopper Activity
Detects cscript VBScript shell execution and csvde writing log files into C:\windows\web\.
sigmahigh2017-04-07Windows Service Install (Event ID 7045) for srservice, ipvpn, hkmsvc
Alerts on Windows service creation events (7045) for srservice, ipvpn, and hkmsvc service names.
sigmahigh2017-03-31Windows Registry UAC Bypass via Event Viewer Command Key (mscfile shell open command)
Alerts on registry changes to the mscfile shell open command key consistent with an Event Viewer UAC bypass technique.
sigmaWindowshigh2017-03-19Windows Event Viewer (eventvwr.exe) Spawns Suspicious Child Processes
Alerts when eventvwr.exe spawns unusual child processes in Windows process creation logs.
sigmaWindowshigh2017-03-19Windows Network Connections to Known Malware Callback Ports (Suspicious Destination Ports)
Flags Windows processes initiating outbound connections to malware callback ports, excluding local/private IP ranges.
sigmaWindowshigh2017-03-19Windows network connection from process running in suspicious or uncommon file paths
Alerts on Windows network connections initiated by processes executing from suspicious or uncommon directories.
sigmaWindowshigh2017-03-19Windows UAC Bypass Indicator via sdclt Registry Key Manipulation
Alerts on registry set activity consistent with sdclt-related UAC bypass key manipulation.
sigmaWindowshigh2017-03-17Linux Log Shellshock Expression Pattern Matching
Identifies Shellshock-style function-body expressions in Linux log data via keyword string matches.
sigmaLinuxhigh2017-03-14Windows PowerShell ScriptBlock with Encoded, Hidden, or Noninteractive Execution Parameters
Alerts on PowerShell ScriptBlockText containing encoded command, hidden window, or noninteractive execution parameters.
sigmaWindowshigh2017-03-12Suspicious PowerShell Module Execution Using Encoded, Hidden, or Noninteractive Context (Windows)
Alerts on PowerShell module executions using encoded commands, hidden windows, or noninteractive flags to evade visibility and interaction.
sigmaWindowshigh2017-03-12Windows Security: Detects SAM User/Group Access During Domain Recon (Event ID 4661)
Alerts on Event ID 4661 accesses to SAM user/group objects for domain Administrator and Domain Admins.
sigmaWindowshigh2017-03-07Windows Service Install: NtsSrv (StoneDrill) via Service Control Manager Event 7045
Flags Windows service installs of NtsSrv by Service Control Manager with an ImagePath ending in " LocalService".
sigmahigh2017-03-07Suspicious PowerShell Script Block Invocations Using Encoded/Hidden Execution and Persistence Commands
Flags PowerShell script blocks using hidden/non-interactive execution, encoded/decode patterns, iex execution, web downloads, or run key modifications.
sigmaWindowshigh2017-03-05Windows PowerShell Script Block Logging: PSAttack marker string
Alerts when PowerShell script blocks contain the "PS ATTACK!!!" marker on Windows.
sigmaWindowshigh2017-03-05Windows PowerShell ScriptBlock detects known malicious commandlet names used by exploitation frameworks
Alerts when PowerShell ScriptBlock text includes strings matching known malicious commandlets from common exploitation toolsets.
sigmaWindowshigh2017-03-05Suspicious PowerShell Module Usage with Hidden/Encoded Execution Parameters on Windows
Flags hidden or encoded PowerShell invocations that decode/execute code or download-and-execute patterns, while filtering a Chocolatey installer snippet.
sigmaWindowshigh2017-03-05Windows PowerShell Execution via EngineVersion/HostVersion Mismatch in Command Start Telemetry
Detects PowerShell execution attempts that match a specific executable EngineVersion/HostVersion mismatch pattern on Windows.
sigmaWindowshigh2017-03-05Windows System Service Execution of Credential Dumping Tools (Service Control Manager Event 7045)
Flags Service Control Manager service creation with ImagePath names tied to credential dumping tools (Event ID 7045).
sigmaWindowshigh2017-03-05