Every published rule
Every rule shows the reporting behind it, the telemetry it needs and where it falls short — before it costs you anything.
330 rules
Azure Entra ID Sign-ins with User-Agent Containing "axios"
Flags Azure Entra ID sign-ins with a user agent containing "axios", indicating potential automated sign-in activity.
sigmalow2026-04-28Proxy requests to EvilTokens PhaaS phishing domains (Cloudflare Workers, Railway.app)
Alerts on proxy requests to Cloudflare Workers or Railway.app URLs associated with EvilTokens phishing PhaaS kit infrastructure.
sigmalow2026-04-28Linux setcap sets cap_setuid on a binary via setcap utility
Alerts on Linux executions of setcap configuring cap_setuid on a binary, indicating potential identity-manipulation and persistence risk.
sigmaLinuxlow2026-01-24Linux setcap sets cap_setgid on binaries (Setgid capability assignment)
Flags Linux setcap commands that set cap_setgid on binaries via process creation logs.
sigmaLinuxlow2026-01-24Web Browser Opens .HTM/.HTML from Downloads Folder on Windows
Flags browser processes opening .htm files from a user’s Downloads folder on Windows, a pattern consistent with HTML attachment activity.
sigmalow2025-12-05Linux File Creation with Unusually Long Filenames (100+ Characters)
Flags Linux file creations with filenames 100+ characters long, excluding specific known benign system paths, to support threat hunting.
sigmalow2025-11-22Windows: Detect Advanced Installer PSF AI_STUBS Executables with OriginalFileName popupwrapper.exe
Flags Windows execution of Advanced Installer PSF AI_STUBS stubs where OriginalFileName equals popupwrapper.exe.
sigmaWindowslow2025-11-03Windows: Successful MSIX/AppX Package Installation via AppX Deployment Server (Event ID 854)
Flags successful MSIX/AppX package installations on Windows using EventID 854 from the AppXDeployment-Server operational log.
sigmalow2025-11-03GitHub Audit Events: Repository Archived/Unarchived Status Change
Alerts on GitHub audit events indicating a repository was archived or unarchived.
sigmalow2025-10-18GitHub Pages repository site changed to public (repo.pages_public audit event)
Flags when a GitHub repository’s Pages site visibility is changed to public in the audit log.
sigmalow2025-10-18Windows Process Creation: Executable Launches Identical Self Instance (Sacrificial Process)
Alerts on Windows process creation where a targeted parent context suggests an executable spawns an identical instance, potentially as a sacrificial process.
sigmalow2025-10-17Linux sudo --chroot Command Execution
Identifies Linux executions of sudo with chroot-related options ("--chroot" or "-R") via process creation command-line telemetry.
sigmaLinuxlow2025-10-02Windows Process Information Discovery via Registry Queries (reg.exe/powershell)
Flags reg.exe and PowerShell registry queries used to enumerate OS, Defender, installed apps, timezone, and services.
sigmaWindowslow2025-06-12RegAsm.exe Process Execution Missing Command-Line and Assembly Path (Windows)
Alert on RegAsm.exe process creation when the command line lacks typical Regasm flags or file parameters.
sigmaWindowslow2025-06-04Windows Process Loaded BitsProxy.dll via Uncommon Image
Alert on image loads of BitsProxy.dll by processes outside an allowlist of common Windows BITS-related executables.
sigmalow2025-06-04Linux mknod Syscall Used to Create Special Files
Flags mknod syscall activity in Linux auditd, indicating special file/device node creation.
sigmaLinuxlow2025-05-31Linux sysinfo Syscall for System Information Discovery
Detects auditd-reported sysinfo syscalls on Linux that can indicate system fingerprinting or reconnaissance.
sigmaLinuxlow2025-05-30Windows PowerShell Modifies dMSA msDS-ManagedAccountPrecededByLink Attributes
Flags PowerShell script content modifying msDS-ManagedAccountPrecededByLink (dMSA link attributes) via AD link changes.
sigmaWindowslow2025-05-24Windows: Deno writes files from remote HTTPS content into AppData
Alerts when Deno writes to user AppData while using remote HTTPS download-style paths.
sigmaWindowslow2025-05-22Windows File Access to Browser Credential Storage by Non-Browser Processes
Flags non-browser processes reading common browser credential storage files on Windows, indicating potential credential theft.
sigmaWindowslow2025-05-22