Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
167 rules
Windows Named Pipe Creation Alert for Known Malicious Pipe Names
Alert on Windows named pipe creations where the PipeName matches known malware-associated pipe identifiers.
sigmaWindowscritical2017-11-06Windows Named Pipe Creation Matching Suspected Turla Pipe Names
Alert on Windows named pipe creation when the PipeName matches Turla-associated strings.
sigmacritical2017-11-06Windows: Winword spawning csc.exe indicative of CVE-2017-8759 exploitation
Flags Word (WINWORD.EXE) spawning csc.exe, a suspicious execution pattern observed in some exploit chains.
sigmacritical2017-09-15Windows rundll32 execution matching ZxShell function and remote disk strings
Alerts on rundll32.exe command lines containing zxFunction and RemoteDiskXXXXX indicative of ZxShell execution.
sigmacritical2017-07-20Windows WCE wceaux.dll File Access via Security Event 4656/4663
Identifies Windows Security event activity involving access to the wceaux.dll library file.
sigmaWindowscritical2017-06-14Windows Registry Event: Pandemic implant key path contains null Instance
Detects registry activity targeting CurrentControlSet\services\null\Instance, associated with Windows implant persistence staging.
sigmacritical2017-06-01Windows Service Creation: ServiceName javamtsup (Event ID 4697)
Flags Windows Security Event 4697 when a service named "javamtsup" is installed, indicating potential persistence.
sigmacritical2017-03-27