Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
14 rules
Windows: BlueSky ransomware-related file and share access events
Alerts on Windows file/share access involving .bluesky and "DECRYPT FILES BLUESKY" artifact naming tied to BlueSky activity.
sigmahigh2023-05-23Windows: Rorschach execution indicator via critical command-line pattern
Windows process creation events with certain system utilities and a "11111111" command-line marker are flagged as ransomware execution activity.
sigmacritical2023-04-04Windows Registry Ransom Note Keyword Changes in LegalNoticeCaption/Text
Alerts on registry changes to Windows legal notice caption/text containing ransomware-style keywords.
sigmaWindowshigh2022-12-11Antivirus ransomware signature match (Babuk, Lockbit, Ryuk, WannaCry)
Flags antivirus ransomware detections when the alert signature contains known ransomware family name strings.
sigmacritical2022-05-12Windows Process Command-Line Indicators of BlackByte Ransomware Activity
Flags Windows process creation command-line patterns consistent with BlackByte ransomware techniques.
sigmahigh2022-02-25BlackByte ransomware Registry Set Persistence and Privilege Changes (Windows)
Alerts on BlackByte-specific Windows registry value changes to DWORD 1 across three predefined keys.
sigmahigh2022-01-24Windows: .txt Created on User Desktop via cmd.exe
Flags cmd.exe creating .txt files under user Desktop, a common ransomware-style artifact placement pattern.
sigmamedium2021-12-26Microsoft 365 Cloud App Security - Potential Ransomware Activity Alerts on File Upload
Flags successful Microsoft Cloud App Security reports of potential ransomware-related file uploads in Microsoft 365.
sigmaCloudmedium2021-08-19Windows process creation patterns associated with DarkSide ransomware helpers
Detects Windows process creation consistent with DarkSide ransomware helper execution using encoded command-line content.
sigmacritical2021-05-14LockerGoga Ransomware Indicators in Windows Process Command Line
Flags Windows processes with a specific LockerGoga-style command-line argument pattern.
sigmacritical2020-10-18Windows Process Creation Indicators for Snatch Ransomware Word Document Droppers
Alerts on Windows process command lines showing instant safe-mode shutdown/reboot and stopping SuperBackupMan service.
sigmahigh2020-08-26Windows Process Creation: Maze Ransomware Doc Dropper and Shadow Copy Deletion Indicators
Alerts on Word-to-temp execution followed by wmic shadowcopy deletion consistent with Maze-style ransomware droppers.
sigmacritical2020-05-08Windows Process Execution Indicative of Ryuk-Style Ransomware Behavior
Flags suspicious Windows process command lines combining autorun persistence, public staging, file backup wiping, and service stoppage behavior.
sigmahigh2019-12-16Windows Application Logs: Match Antivirus Signature and Malware Keyword Hits
Alerts on Windows application log lines containing known AV signatures and malware keywords, excluding some anti-ransomware/keygen/crack terms.
sigmaWindowshigh2017-02-19