Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
1656 rules
Windows Security EID 4697 Service Execution of Credential Dumping Tools
Alerts on Event ID 4697 service execution paths containing common credential dumping tool names on Windows.
sigmaWindowshigh2017-03-05Windows process access targeting verclsid.exe with Office/VBA shellcode traces
Flags broad access to verclsid.exe from Microsoft Office/VBA contexts with VBE7.DLL call traces consistent with shellcode injection.
sigmahigh2017-03-04Linux Syslog Buffer Overflow Exploit Attempt Keywords
Alerts on Linux syslog entries containing known buffer overflow/stack-smashing attempt keyword patterns.
sigmaLinuxhigh2017-03-01Linux ClamAV alerts for Trojan, Webshell, Rootkit, Htran, VirTool detections
Detects ClamAV log entries with keyword-based indicators for Trojans, webshells, rootkits, and Htran.
sigmaLinuxhigh2017-03-01Apache worker crash logs with "Segmentation Fault" exit signal
Alerts on Apache error log lines showing a worker process crashed with an exit signal Segmentation Fault.
sigmaWebhigh2017-02-28Windows LSASS Remote Thread Creation Indicative of Password Dumping
Flags Windows remote thread creation targeting lsass.exe, a common pattern in password dumping activity.
sigmaWindowshigh2017-02-19Windows Security Event 4794 Password Change for DSRM Account
Flags potential changes to the DSRM administrator password on Windows domain controllers using Security EventID 4794.
sigmaWindowshigh2017-02-19Windows Application Logs: Match Antivirus Signature and Malware Keyword Hits
Alerts on Windows application log lines containing known AV signatures and malware keywords, excluding some anti-ransomware/keygen/crack terms.
sigmaWindowshigh2017-02-19Windows Webshell Command Strings in Webserver GET Requests
Identifies GET requests with URL-encoded Windows command strings consistent with webshell behavior.
sigmaWebhigh2017-02-19Windows Driver Load from Temporary Directory Paths
Detects Windows driver loads whose ImageLoaded path contains the temporary directory (\Temp\).
sigmaWindowshigh2017-02-12Windows Security: Detect LSASS handle access for SAM_DOMAIN (0x705)
Flags handle opens to lsass.exe with access mask 0x705 targeting SAM_DOMAIN, indicative of credential dumping.
sigmaWindowshigh2017-02-12Windows Kerberos TGT Issue Operations Failures (Event IDs 675/4768/4769/4771)
Alerts on Windows Security failures for Kerberos TGT-related operations using specific Kerberos event IDs and status codes.
sigmaWindowshigh2017-02-10Windows Event Logs: Mimikatz Keyword Indicators
Detects Mimikatz-related keywords in Windows event logs while filtering Sysmon EventID 15 to limit noise.
sigmaWindowshigh2017-01-10Windows Security and Eventlog Cleared via Event IDs 517 or 1102
Flags Windows event log clearing using Security Event ID 517 and Microsoft-Windows-Eventlog Event ID 1102.
sigmaWindowshigh2017-01-10Windows Webshell Recon Command-Line Keywords via Web Server Processes
Flags Windows process chains where web server parents spawn reconnaissance- and execution-related command lines indicative of webshell activity.
sigmaWindowshigh2017-01-01Windows WerFault Access to lsass.exe Indicative of Credential Dumping Attempts
Alert on WerFault.exe gaining broad access to lsass.exe, consistent with credential dumping attempts.
sigmaWindowshigh2012-06-27