1200KM / tag
high — severity tag
1290 related reference pages for severity: high.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- Abusable DLL Potential Sideloading From Suspicious Location · sigma-rule
- Abuse of Service Permissions to Hide Services Via Set-Service · sigma-rule
- Abuse of Service Permissions to Hide Services Via Set-Service - PS · sigma-rule
- Abused Debug Privilege by Arbitrary Parent Processes · sigma-rule
- Account Created And Deleted Within A Close Time Frame · sigma-rule
- Active Directory User Backdoors · sigma-rule
- Activity From Anonymous IP Address · sigma-rule
- AD Privileged Users or Groups Reconnaissance · sigma-rule
- Add Insecure Download Source To Winget · sigma-rule
- Add SafeBoot Keys Via Reg Utility · sigma-rule
- Added Credentials to Existing Application · sigma-rule
- Adwind RAT / JRAT File Artifact · sigma-rule
- All Backups Deleted Via Wbadmin.EXE · sigma-rule
- All Rules Have Been Deleted From The Windows Firewall Configuration · sigma-rule
- Allow Service Access Using Security Descriptor Tampering Via Sc.EXE · sigma-rule
- AMSI Bypass Pattern Assembly GetType · sigma-rule
- AMSI Disabled via Registry Modification · sigma-rule
- Anomalous Token · sigma-rule
- Anomalous User Activity · sigma-rule
- Anonymous IP Address · sigma-rule
- Antivirus Filter Driver Disallowed On Dev Drive - Registry · sigma-rule
- Antivirus Hacktool Detection · sigma-rule
- Antivirus Relevant File Paths Alerts · sigma-rule
- Antivirus Web Shell Detection · sigma-rule
- Apache Segmentation Fault · sigma-rule
- App Granted Microsoft Permissions · sigma-rule
- App Granted Privileged Delegated Or App Permissions · sigma-rule
- Application AppID Uri Configuration Changes · sigma-rule
- Application URI Configuration Changes · sigma-rule
- APT User Agent · sigma-rule
- Arbitrary File Download Via IMEWDBLD.EXE · sigma-rule
- Aruba Network Service Potential DLL Sideloading · sigma-rule
- ASLR Disabled Via Sysctl or Direct Syscall - Linux · sigma-rule
- Atera Agent Installation · sigma-rule
- Attempts of Kerberos Coercion Via DNS SPN Spoofing · sigma-rule
- Atypical Travel · sigma-rule
- Audit Policy Tampering Via Auditpol · sigma-rule
- Audit Policy Tampering Via NT Resource Kit Auditpol · sigma-rule
- Audit Rules Deleted Via Auditctl · sigma-rule
- Auditing Configuration Changes on Linux Host · sigma-rule
- AWS Config Disabling Channel/Recorder · sigma-rule
- AWS EC2 Startup Shell Script Change · sigma-rule
- AWS GuardDuty Detector Deleted Or Updated · sigma-rule
- AWS GuardDuty Important Change · sigma-rule
- AWS IAM S3Browser LoginProfile Creation · sigma-rule
- AWS IAM S3Browser Templated S3 Bucket Policy Creation · sigma-rule
- AWS IAM S3Browser User or AccessKey Creation · sigma-rule
- AWS Identity Center Identity Provider Change · sigma-rule
- AWS KMS Imported Key Material Usage · sigma-rule
- AWS SecurityHub Findings Evasion · sigma-rule
- AWS User Login Profile Was Modified · sigma-rule
- Azure AD Account Credential Leaked · sigma-rule
- Azure AD Threat Intelligence · sigma-rule
- Azure Login Bypassing Conditional Access Policies · sigma-rule
- Azure Subscription Permission Elevation Via ActivityLogs · sigma-rule
- Azure Subscription Permission Elevation Via AuditLogs · sigma-rule
- BaaUpdate.exe Suspicious DLL Load · sigma-rule
- Bad Opsec Defaults Sacrificial Processes With Improper Arguments · sigma-rule
- Base64 Encoded PowerShell Command Detected · sigma-rule
- Binary Padding - Linux · sigma-rule
- Binary Padding - MacOS · sigma-rule
- Bitbucket Full Data Export Triggered · sigma-rule
- Bitbucket Secret Scanning Exempt Repository Added · sigma-rule
- BITS Transfer Job Download From Direct IP · sigma-rule
- BITS Transfer Job Download From File Sharing Domains · sigma-rule
- BITS Transfer Job Download To Potential Suspicious Folder · sigma-rule
- Bitsadmin to Uncommon IP Server Address · sigma-rule
- Bitsadmin to Uncommon TLD · sigma-rule
- BloodHound Collection Files · sigma-rule
- Boot Configuration Tampering Via Bcdedit.EXE · sigma-rule
- BPFDoor Abnormal Process ID or Lock File Accessed · sigma-rule
- Buffer Overflow Attempts · sigma-rule
- Bulk Deletion Changes To Privileged Account Permissions · sigma-rule
- Bypass UAC Using DelegateExecute · sigma-rule
- Bypass UAC Using Event Viewer · sigma-rule
- Bypass UAC Using SilentCleanup Task · sigma-rule
- Bypass UAC via CMSTP · sigma-rule
- Bypass UAC via Fodhelper.exe · sigma-rule
- Bypass UAC via WSReset.exe · sigma-rule
- Capsh Shell Invocation - Linux · sigma-rule
- Change Default File Association To Executable Via Assoc · sigma-rule
- Change the Fax Dll · sigma-rule
- Change User Account Associated with the FAX Service · sigma-rule
- Change Winevt Channel Access Permission Via Registry · sigma-rule
- Changes to Device Registration Policy · sigma-rule
- Changes To PIM Settings · sigma-rule
- Chopper Webshell Process Pattern · sigma-rule
- Cisco Clear Logs · sigma-rule
- Cisco Crypto Commands · sigma-rule
- Cisco Disabling Logging · sigma-rule
- Cisco Local Accounts · sigma-rule
- Clearing Windows Console History · sigma-rule
- Cmd.EXE Missing Space Characters Execution Anomaly · sigma-rule
- CMSTP Execution Process Access · sigma-rule
- CMSTP Execution Process Creation · sigma-rule
- CMSTP Execution Registry Event · sigma-rule
- CMSTP UAC Bypass via COM Object Access · sigma-rule
- CobaltStrike Load by Rundll32 · sigma-rule
- CobaltStrike Named Pipe Patterns · sigma-rule
- CobaltStrike Service Installations - Security · sigma-rule
- Code Executed Via Office Add-in XLL File · sigma-rule
- Code Injection by ld.so Preload · sigma-rule
- CodeIntegrity - Blocked Driver Load With Revoked Certificate · sigma-rule
- CodeIntegrity - Blocked Image/Driver Load For Policy Violation · sigma-rule
- COM Hijack via Sdclt · sigma-rule
- COM Object Hijacking Via Modification Of Default System CLSID Default Value · sigma-rule
- Commands to Clear or Remove the Syslog - Builtin · sigma-rule
- Communication To LocaltoNet Tunneling Service Initiated · sigma-rule
- Communication To LocaltoNet Tunneling Service Initiated - Linux · sigma-rule
- Communication To Ngrok Tunneling Service - Linux · sigma-rule
- Communication To Ngrok Tunneling Service Initiated · sigma-rule
- Conhost.exe CommandLine Path Traversal · sigma-rule
- Control Panel Items · sigma-rule
- Copy From VolumeShadowCopy Via Cmd.EXE · sigma-rule
- Copy Passwd Or Shadow From TMP Path · sigma-rule
- Copying Sensitive Files with Credential Data · sigma-rule
- Create Volume Shadow Copy with Powershell · sigma-rule
- CreateDump Process Dump · sigma-rule
- Creation Exe for Service with Unquoted Path · sigma-rule
- Creation of a Local Hidden User Account by Registry · sigma-rule
- Cred Dump Tools Dropped Files · sigma-rule
- Credential Dumping Activity By Python Based Tool · sigma-rule
- Credential Dumping Attempt Via Svchost · sigma-rule
- Credential Dumping Attempt Via WerFault · sigma-rule
- Credential Dumping Tools Service Execution - Security · sigma-rule
- Credential Dumping Tools Service Execution - System · sigma-rule
- Credentials In Files · sigma-rule
- Credentials In Files - Linux · sigma-rule
- Critical Hive In Suspicious Location Access Bits Cleared · sigma-rule
- Cross Site Scripting Strings · sigma-rule
- Crypto Miner User Agent · sigma-rule
- Csc.EXE Execution Form Potentially Suspicious Parent · sigma-rule
- Cscript/Wscript Uncommon Script Extension Execution · sigma-rule
- Curl Download And Execute Combination · sigma-rule
- Curl File Upload To File Sharing Websites · sigma-rule
- Custom File Open Handler Executes PowerShell · sigma-rule
- DCOM InternetExplorer.Application Iertutil DLL Hijack - Security · sigma-rule
- Default RDP Port Changed to Non Standard Port · sigma-rule
- Delegated Permissions Granted For All Users · sigma-rule
- Delete All Scheduled Tasks · sigma-rule
- Delete Important Scheduled Task · sigma-rule
- Delete Volume Shadow Copies Via WMI With PowerShell · sigma-rule
- Deletion of Volume Shadow Copies via WMI with PowerShell · sigma-rule
- Deletion of Volume Shadow Copies via WMI with PowerShell - PS Script · sigma-rule
- Deny Service Access Using Security Descriptor Tampering Via Sc.EXE · sigma-rule
- Devcon Execution Disabling VMware VMCI Device · sigma-rule
- Devtoolslauncher.exe Executes Specified Binary · sigma-rule
- DHCP Callout DLL Installation · sigma-rule
- DHCP Server Error Failed Loading the CallOut DLL · sigma-rule
- DHCP Server Loaded the CallOut DLL · sigma-rule
- Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE · sigma-rule
- Directory Service Restore Mode(DSRM) Registry Value Tampering · sigma-rule
- Disable Important Scheduled Task · sigma-rule
- Disable of ETW Trace - Powershell · sigma-rule
- Disable Powershell Command History · sigma-rule
- Disable PUA Protection on Windows Defender · sigma-rule
- Disable Security Events Logging Adding Reg Key MiniNt · sigma-rule
- Disable System Firewall · sigma-rule
- Disable Windows Defender AV Security Monitoring · sigma-rule
- Disable Windows Defender Functionalities Via Registry Keys · sigma-rule
- Disable Windows Event Logging Via Registry · sigma-rule
- Disable Windows IIS HTTP Logging · sigma-rule
- Disable-WindowsOptionalFeature Command PowerShell · sigma-rule
- Disabled IE Security Features · sigma-rule
- Disabled Volume Snapshots · sigma-rule
- Disabled Windows Defender Eventlog · sigma-rule
- Disabling Multi Factor Authentication · sigma-rule
- Disabling Windows Defender WMI Autologger Session via Reg.exe · sigma-rule
- Discovery Using AzureHound · sigma-rule
- DLL Load via LSASS · sigma-rule
- DLL Loaded From Suspicious Location Via Cmspt.EXE · sigma-rule
- DLL Search Order Hijackig Via Additional Space in Path · sigma-rule
- DLL Sideloading by VMware Xfer Utility · sigma-rule
- DLL Sideloading Of ShellChromeAPI.DLL · sigma-rule
- Dllhost.EXE Execution Anomaly · sigma-rule
- DNS Exfiltration and Tunneling Tools Execution · sigma-rule
- DNS HybridConnectionManager Service Bus · sigma-rule
- DNS Query by Finger Utility · sigma-rule
- DNS Query for Anonfiles.com Domain - DNS Client · sigma-rule
- DNS Query for Anonfiles.com Domain - Sysmon · sigma-rule
- DNS Query to External Service Interaction Domains · sigma-rule
- DNS Query Tor .Onion Address - Sysmon · sigma-rule
- DNS Server Error Failed Loading the ServerLevelPluginDLL · sigma-rule
- DNS TXT Answer with Possible Execution Strings · sigma-rule
- DotNet CLR DLL Loaded By Scripting Applications · sigma-rule
- DPAPI Backup Keys And Certificate Export Activity IOC · sigma-rule
- DPAPI Domain Backup Key Extraction · sigma-rule
- Driver Load From A Temporary Directory · sigma-rule
- DSInternals Suspicious PowerShell Cmdlets · sigma-rule
- DSInternals Suspicious PowerShell Cmdlets - ScriptBlock · sigma-rule
- Dumping of Sensitive Hives Via Reg.EXE · sigma-rule
- Enable LM Hash Storage · sigma-rule
- Enable LM Hash Storage - ProcCreation · sigma-rule
- Enabled User Right in AD to Control User Objects · sigma-rule
- Equation Group Indicators · sigma-rule
- Esentutl Volume Shadow Copy Service Keys · sigma-rule
- ESXi Admin Permission Assigned To Account Via ESXCLI · sigma-rule
- ETW Logging Disabled In .NET Processes - Registry · sigma-rule
- ETW Logging Disabled In .NET Processes - Sysmon Registry · sigma-rule
- ETW Logging Tamper In .NET Processes Via CommandLine · sigma-rule
- ETW Trace Evasion Activity · sigma-rule
- Exchange PowerShell Cmdlet History Deleted · sigma-rule
- Exchange PowerShell Snap-Ins Usage · sigma-rule
- Exchange Set OabVirtualDirectory ExternalUrl Property · sigma-rule
- Execute Pcwrun.EXE To Leverage Follina · sigma-rule
- Execution DLL of Choice Using WAB.EXE · sigma-rule
- Execution of Powershell Script in Public Folder · sigma-rule
- Execution via stordiag.exe · sigma-rule
- Execution via WorkFolders.exe · sigma-rule
- Exploit Framework User Agent · sigma-rule
- Explorer NOUACCHECK Flag · sigma-rule
- Exports Critical Registry Keys To a File · sigma-rule
- Exports Registry Key To an Alternate Data Stream · sigma-rule
- External Remote SMB Logon from Public IP · sigma-rule
- Failed MSExchange Transport Agent Installation · sigma-rule
- Fax Service DLL Search Order Hijack · sigma-rule
- File Creation In Suspicious Directory By Msdt.EXE · sigma-rule
- File Decoded From Base64/Hex Via Certutil.EXE · sigma-rule
- File Download And Execution Via IEExec.EXE · sigma-rule
- File Download From IP Based URL Via CertOC.EXE · sigma-rule
- File Download Using Notepad++ GUP Utility · sigma-rule
- File Download Via Bitsadmin To A Suspicious Target Folder · sigma-rule
- File Download Via Windows Defender MpCmpRun.EXE · sigma-rule
- File Download with Headless Browser · sigma-rule
- File Explorer Folder Opened Using Explorer Folder Shortcut Via Shell · sigma-rule
- File In Suspicious Location Encoded To Base64 Via Certutil.EXE · sigma-rule
- File With Suspicious Extension Downloaded Via Bitsadmin · sigma-rule
- File With Uncommon Extension Created By An Office Application · sigma-rule
- FileFix - Command Evidence in TypedPaths · sigma-rule
- Findstr GPP Passwords · sigma-rule
- Finger.EXE Execution · sigma-rule
- First Time Seen Remote Named Pipe · sigma-rule
- First Time Seen Remote Named Pipe - Zeek · sigma-rule
- Flash Player Update from Suspicious Location · sigma-rule
- Folder Removed From Exploit Guard ProtectedFolders List - Registry · sigma-rule
- Forfiles.EXE Child Process Masquerading · sigma-rule
- Fsutil Suspicious Invocation · sigma-rule
- GAC DLL Loaded Via Office Applications · sigma-rule
- Github High Risk Configuration Disabled · sigma-rule
- Github Push Protection Disabled · sigma-rule
- Github Secret Scanning Feature Disabled · sigma-rule
- Guacamole Two Users Sharing Session Anomaly · sigma-rule
- Hack Tool User Agent · sigma-rule
- HackTool - ADCSPwn Execution · sigma-rule
- HackTool - Bloodhound/Sharphound Execution · sigma-rule
- HackTool - CACTUSTORCH Remote Thread Creation · sigma-rule
- HackTool - Certify Execution · sigma-rule
- HackTool - Certipy Execution · sigma-rule
- HackTool - CobaltStrike BOF Injection Pattern · sigma-rule
- HackTool - CobaltStrike Malleable Profile Patterns - Proxy · sigma-rule
- HackTool - CoercedPotato Execution · sigma-rule
- HackTool - CoercedPotato Named Pipe Creation · sigma-rule
- HackTool - Covenant PowerShell Launcher · sigma-rule
- HackTool - CrackMapExec Execution · sigma-rule
- HackTool - CrackMapExec Execution Patterns · sigma-rule
- HackTool - CrackMapExec File Indicators · sigma-rule
- HackTool - CrackMapExec PowerShell Obfuscation · sigma-rule
- HackTool - CrackMapExec Process Patterns · sigma-rule
- HackTool - CreateMiniDump Execution · sigma-rule
- HackTool - Default PowerSploit/Empire Scheduled Task Creation · sigma-rule
- HackTool - Doppelanger LSASS Dumper Execution · sigma-rule
- Hacktool - EDR-Freeze Execution · sigma-rule
- HackTool - EDRSilencer Execution · sigma-rule
- HackTool - EDRSilencer Execution - Filter Added · sigma-rule
- HackTool - EfsPotato Named Pipe Creation · sigma-rule
- HackTool - Empire PowerShell Launch Parameters · sigma-rule
- HackTool - Empire UserAgent URI Combo · sigma-rule
- HackTool - Generic Process Access · sigma-rule
- HackTool - HandleKatz Duplicating LSASS Handle · sigma-rule
- HackTool - HandleKatz LSASS Dumper Execution · sigma-rule
- HackTool - Hashcat Password Cracker Execution · sigma-rule
- HackTool - HollowReaper Execution · sigma-rule
- HackTool - Htran/NATBypass Execution · sigma-rule
- HackTool - Hydra Password Bruteforce Execution · sigma-rule
- HackTool - Impacket File Indicators · sigma-rule
- HackTool - Impacket Tools Execution · sigma-rule
- HackTool - Koadic Execution · sigma-rule
- HackTool - KrbRelay Execution · sigma-rule
- HackTool - KrbRelayUp Execution · sigma-rule
- HackTool - LittleCorporal Generated Maldoc Injection · sigma-rule
- HackTool - Mimikatz Execution · sigma-rule
- HackTool - NetExec Execution · sigma-rule
- HackTool - NetExec File Indicators · sigma-rule
- HackTool - NoFilter Execution · sigma-rule
- HackTool - PCHunter Execution · sigma-rule
- HackTool - Potential CobaltStrike Process Injection · sigma-rule
- HackTool - Potential Impacket Lateral Movement Activity · sigma-rule
- HackTool - Potential Remote Credential Dumping Activity Via CrackMapExec Or Impacket-Secretsdump · sigma-rule
- HackTool - PowerTool Execution · sigma-rule
- HackTool - Powerup Write Hijack DLL · sigma-rule
- HackTool - PPID Spoofing SelectMyParent Tool Execution · sigma-rule
- HackTool - Pypykatz Credentials Dumping Activity · sigma-rule
- HackTool - Quarks PwDump Execution · sigma-rule
- HackTool - RedMimicry Winnti Playbook Execution · sigma-rule
- HackTool - RemoteKrbRelay Execution · sigma-rule
- HackTool - RemoteKrbRelay SMB Relay Secrets Dump Module Indicators · sigma-rule
- HackTool - Rubeus Execution - ScriptBlock · sigma-rule
- HackTool - SafetyKatz Dump Indicator · sigma-rule
- HackTool - SharpChisel Execution · sigma-rule
- HackTool - SharpDPAPI Execution · sigma-rule
- HackTool - SharPersist Execution · sigma-rule
- HackTool - SharpEvtMute DLL Load · sigma-rule
- HackTool - SharpEvtMute Execution · sigma-rule
- HackTool - SharpImpersonation Execution · sigma-rule
- HackTool - SharpLdapWhoami Execution · sigma-rule
- HackTool - SharpMove Tool Execution · sigma-rule
- HackTool - SharpView Execution · sigma-rule
- HackTool - SharpWSUS/WSUSpendu Execution · sigma-rule
- HackTool - SILENTTRINITY Stager DLL Load · sigma-rule
- HackTool - SILENTTRINITY Stager Execution · sigma-rule
- HackTool - SOAPHound Execution · sigma-rule
- HackTool - Stracciatella Execution · sigma-rule
- HackTool - SysmonEnte Execution · sigma-rule
- HackTool - TruffleSnout Execution · sigma-rule
- HackTool - Typical HiveNightmare SAM File Export · sigma-rule
- HackTool - UACMe Akagi Execution · sigma-rule
- HackTool - winPEAS Execution · sigma-rule
- HackTool - WinPwn Execution · sigma-rule
- HackTool - WinPwn Execution - ScriptBlock · sigma-rule
- HackTool - WSASS Execution · sigma-rule
- HackTool - XORDump Execution · sigma-rule
- Hacktool Execution - PE Metadata · sigma-rule
- HackTool Named File Stream Created · sigma-rule
- Hacktool Ruler · sigma-rule
- HackTool Service Registration or Execution · sigma-rule
- Hidden Local User Creation · sigma-rule
- Hide Schedule Task Via Index Value Tamper · sigma-rule
- Hiding User Account Via SpecialAccounts Registry Key · sigma-rule
- Hijack Legit RDP Session to Move Laterally · sigma-rule
- History File Deletion · sigma-rule
- HKTL - SharpSuccessor Privilege Escalation Tool Execution · sigma-rule
- HTML Help HH.EXE Suspicious Child Process · sigma-rule
- HTTP Logging Disabled On IIS Server · sigma-rule
- HybridConnectionManager Service Installation · sigma-rule
- HybridConnectionManager Service Installation - Registry · sigma-rule
- HybridConnectionManager Service Running · sigma-rule
- Hypervisor Enforced Paging Translation Disabled · sigma-rule
- Hypervisor-protected Code Integrity (HVCI) Related Registry Tampering Via CommandLine · sigma-rule
- Impacket PsExec Execution · sigma-rule
- Important Scheduled Task Deleted or Disabled · sigma-rule
- Important Scheduled Task Deleted/Disabled · sigma-rule
- Important Windows Event Auditing Disabled · sigma-rule
- Important Windows Eventlog Cleared · sigma-rule
- Imports Registry Key From an ADS · sigma-rule
- Impossible Travel · sigma-rule
- Inline Python Execution - Spawn Shell Via OS System Library · sigma-rule
- Installation of WSL Kali-Linux · sigma-rule
- Interactive AT Job · sigma-rule
- Invalid PIM License · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - PowerShell · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - Security · sigma-rule
- Invoke-Obfuscation CLIP+ Launcher - System · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - PowerShell Module · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - Security · sigma-rule
- Invoke-Obfuscation Obfuscated IEX Invocation - System · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - Powershell · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - Security · sigma-rule
- Invoke-Obfuscation STDIN+ Launcher - System · sigma-rule
- Invoke-Obfuscation VAR+ Launcher · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - PowerShell · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - PowerShell Module · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - Security · sigma-rule
- Invoke-Obfuscation VAR+ Launcher - System · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - PowerShell Module · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - Security · sigma-rule
- Invoke-Obfuscation VAR++ LAUNCHER OBFUSCATION - System · sigma-rule
- Invoke-Obfuscation Via Stdin · sigma-rule
- Invoke-Obfuscation Via Stdin - Powershell · sigma-rule
- Invoke-Obfuscation Via Stdin - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Stdin - Security · sigma-rule
- Invoke-Obfuscation Via Stdin - System · sigma-rule
- Invoke-Obfuscation Via Use Clip · sigma-rule
- Invoke-Obfuscation Via Use Clip - Powershell · sigma-rule
- Invoke-Obfuscation Via Use Clip - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use Clip - Security · sigma-rule
- Invoke-Obfuscation Via Use Clip - System · sigma-rule
- Invoke-Obfuscation Via Use MSHTA · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - PowerShell · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - Security · sigma-rule
- Invoke-Obfuscation Via Use MSHTA - System · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - PowerShell · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - PowerShell Module · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - Security · sigma-rule
- Invoke-Obfuscation Via Use Rundll32 - System · sigma-rule
- ISO File Created Within Temp Folders · sigma-rule
- Java Payload Strings · sigma-rule
- JexBoss Command Sequence · sigma-rule
- JNDIExploit Pattern · sigma-rule
- JXA In-memory Execution Via OSAScript · sigma-rule
- Kaspersky Endpoint Security Stopped Via CommandLine - Linux · sigma-rule
- Kavremover Dropped Binary LOLBIN Usage · sigma-rule
- Kerberos Manipulation · sigma-rule
- KrbRelayUp Service Installation · sigma-rule
- Legitimate Application Dropped Archive · sigma-rule
- Legitimate Application Dropped Executable · sigma-rule
- Legitimate Application Dropped Script · sigma-rule
- Legitimate Application Writing Files In Uncommon Location · sigma-rule
- Linux Command History Tampering · sigma-rule
- Linux Crypto Mining Indicators · sigma-rule
- Linux Crypto Mining Pool Connections · sigma-rule
- Linux HackTool Execution · sigma-rule
- Linux Keylogging with Pam.d · sigma-rule
- Linux Recon Indicators · sigma-rule
- Linux Webshell Indicators · sigma-rule
- Live Memory Dump Using Powershell · sigma-rule
- Load Of RstrtMgr.DLL By A Suspicious Process · sigma-rule
- Loading of Kernel Module via Insmod · sigma-rule
- Local Privilege Escalation Indicator TabTip · sigma-rule
- Logging Configuration Changes on Linux Host · sigma-rule
- LOL-Binary Copied From System Directory · sigma-rule
- Lolbas OneDriveStandaloneUpdater.exe Proxy Download · sigma-rule
- LSASS Access Detected via Attack Surface Reduction · sigma-rule
- LSASS Access From Potentially White-Listed Processes · sigma-rule
- LSASS Dump Keyword In CommandLine · sigma-rule
- Lsass Full Dump Request Via DumpType Registry Settings · sigma-rule
- LSASS Memory Access by Tool With Dump Keyword In Name · sigma-rule
- Lsass Memory Dump via Comsvcs DLL · sigma-rule
- LSASS Process Crashed - Application · sigma-rule
- LSASS Process Dump Artefact In CrashDumps Folder · sigma-rule
- LSASS Process Memory Dump Creation Via Taskmgr.EXE · sigma-rule
- LSASS Process Memory Dump Files · sigma-rule
- LSASS Process Reconnaissance Via Findstr.EXE · sigma-rule
- Macro Enabled In A Potentially Suspicious Document · sigma-rule
- Malicious Base64 Encoded PowerShell Keywords in Command Lines · sigma-rule
- Malicious DLL File Dropped in the Teams or OneDrive Folder · sigma-rule
- Malicious Driver Load · sigma-rule
- Malicious IP Address Sign-In Failure Rate · sigma-rule
- Malicious IP Address Sign-In Suspicious · sigma-rule
- Malicious Nishang PowerShell Commandlets · sigma-rule
- Malicious PowerShell Commandlets - PoshModule · sigma-rule
- Malicious PowerShell Commandlets - ProcessCreation · sigma-rule
- Malicious PowerShell Commandlets - ScriptBlock · sigma-rule
- Malicious PowerShell Scripts - FileCreation · sigma-rule
- Malicious PowerShell Scripts - PoshModule · sigma-rule
- Malicious ShellIntel PowerShell Commandlets · sigma-rule
- Malicious Usage Of IMDS Credentials Outside Of AWS Infrastructure · sigma-rule
- Malware User Agent · sigma-rule
- ManageEngine Endpoint Central Dctask64.EXE Potential Abuse · sigma-rule
- Mask System Power Settings Via Systemctl · sigma-rule
- Mavinject Inject DLL Into Running Process · sigma-rule
- Metasploit Or Impacket Service Installation Via SMB PsExec · sigma-rule
- Metasploit SMB Authentication · sigma-rule
- Meterpreter or Cobalt Strike Getsystem Service Installation - Security · sigma-rule
- Meterpreter or Cobalt Strike Getsystem Service Installation - System · sigma-rule
- Microsoft Defender Blocked from Loading Unsigned DLL · sigma-rule
- Microsoft Defender Tamper Protection Trigger · sigma-rule
- Microsoft IIS Connection Strings Decryption · sigma-rule
- Microsoft IIS Service Account Password Dumped · sigma-rule
- Microsoft Malware Protection Engine Crash · sigma-rule
- Microsoft Malware Protection Engine Crash - WER · sigma-rule
- Microsoft Office DLL Sideload · sigma-rule
- Microsoft Office Protected View Disabled · sigma-rule
- Mimikatz DC Sync · sigma-rule
- Mimikatz Use · sigma-rule
- MMC Executing Files with Reversed Extensions Using RTLO Abuse · sigma-rule
- MMC Spawning Windows Shell · sigma-rule
- MMC20 Lateral Movement · sigma-rule
- Modification of ld.so.preload · sigma-rule
- Modification or Deletion of an AWS RDS Cluster · sigma-rule
- Modify User Shell Folders Startup Value · sigma-rule
- Monero Crypto Coin Mining Pool Lookup · sigma-rule
- MpiExec Lolbin · sigma-rule
- MSDT Execution Via Answer File · sigma-rule
- MSHTA Execution with Suspicious File Extensions · sigma-rule
- Narrator's Feedback-Hub Persistence · sigma-rule
- NET NGenAssemblyUsageLog Registry Key Tamper · sigma-rule
- Net WebClient Casing Anomalies · sigma-rule
- NetNTLM Downgrade Attack · sigma-rule
- NetNTLM Downgrade Attack - Registry · sigma-rule
- Network Communication Initiated To File Sharing Domains From Process Located In Suspicious Folder · sigma-rule
- Network Communication With Crypto Mining Pool · sigma-rule
- Network Connection Initiated By AddinUtil.EXE · sigma-rule
- Network Connection Initiated By Eqnedt32.EXE · sigma-rule
- Network Connection Initiated By IMEWDBLD.EXE · sigma-rule
- Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location · sigma-rule
- Network Connection Initiated via Finger.EXE · sigma-rule
- Network Connection Initiated Via Notepad.EXE · sigma-rule
- Network Reconnaissance Activity · sigma-rule
- New Connection Initiated To Potential Dead Drop Resolver Domain · sigma-rule
- New Country · sigma-rule
- New DNS ServerLevelPluginDll Installed · sigma-rule
- New DNS ServerLevelPluginDll Installed Via Dnscmd.EXE · sigma-rule
- New Firewall Rule Added In Windows Firewall Exception List For Potential Suspicious Application · sigma-rule
- New Netsh Helper DLL Registered From A Suspicious Location · sigma-rule
- New RUN Key Pointing to Suspicious Folder · sigma-rule
- New TimeProviders Registered With Uncommon DLL Name · sigma-rule
- New User Created Via Net.EXE With Never Expire Option · sigma-rule
- NewActiveScriptEventConsumer Creation Attempt via Wmic.EXE · sigma-rule
- Nginx Core Dump · sigma-rule
- Ngrok Usage with Remote Desktop Service · sigma-rule
- Non-privileged Usage of Reg or Powershell · sigma-rule
- NTDS Exfiltration Filename Patterns · sigma-rule
- NTDS.DIT Creation By Uncommon Parent Process · sigma-rule
- NTDS.DIT Creation By Uncommon Process · sigma-rule
- NTFS Alternate Data Stream · sigma-rule
- NTFS Vulnerability Exploitation · sigma-rule
- NTLM Hash Leak Via Curl NTLM Authentication · sigma-rule
- Obfuscated PowerShell MSI Install via WindowsInstaller COM · sigma-rule
- Obfuscated PowerShell OneLiner Execution · sigma-rule
- Octopus Scanner Malware · sigma-rule
- Odbcconf.EXE Suspicious DLL Location · sigma-rule
- Office Macro File Creation From Suspicious Process · sigma-rule
- Office Macros Warning Disabled · sigma-rule
- Okta FastPass Phishing Detection · sigma-rule
- Okta New Admin Console Behaviours · sigma-rule
- Okta Suspicious Activity Reported by End-user · sigma-rule
- Okta User Session Start Via An Anonymising Proxy Service · sigma-rule
- OMIGOD SCX RunAsProvider ExecuteScript · sigma-rule
- OMIGOD SCX RunAsProvider ExecuteShellCommand · sigma-rule
- OneNote.EXE Execution of Malicious Embedded Scripts · sigma-rule
- OpenCanary - FTP Login Attempt · sigma-rule
- OpenCanary - GIT Clone Request · sigma-rule
- OpenCanary - Host Port Scan (SYN Scan) · sigma-rule
- OpenCanary - HTTP GET Request · sigma-rule
- OpenCanary - HTTP POST Login Attempt · sigma-rule
- OpenCanary - HTTPPROXY Login Attempt · sigma-rule
- OpenCanary - MSSQL Login Attempt Via SQLAuth · sigma-rule
- OpenCanary - MSSQL Login Attempt Via Windows Authentication · sigma-rule
- OpenCanary - MySQL Login Attempt · sigma-rule
- OpenCanary - NMAP FIN Scan · sigma-rule
- OpenCanary - NMAP NULL Scan · sigma-rule
- OpenCanary - NMAP OS Scan · sigma-rule
- OpenCanary - NMAP XMAS Scan · sigma-rule
- OpenCanary - NTP Monlist Request · sigma-rule
- OpenCanary - RDP New Connection Attempt · sigma-rule
- OpenCanary - REDIS Action Command Attempt · sigma-rule
- OpenCanary - SIP Request · sigma-rule
- OpenCanary - SMB File Open Request · sigma-rule
- OpenCanary - SNMP OID Request · sigma-rule
- OpenCanary - SSH Login Attempt · sigma-rule
- OpenCanary - SSH New Connection Attempt · sigma-rule
- OpenCanary - Telnet Login Attempt · sigma-rule
- OpenCanary - TFTP Request · sigma-rule
- OpenCanary - VNC Connection Attempt · sigma-rule
- OpenWith.exe Executes Specified Binary · sigma-rule
- Operator Bloopers Cobalt Strike Commands · sigma-rule
- Operator Bloopers Cobalt Strike Modules · sigma-rule
- OSACompile Run-Only Execution · sigma-rule
- Outbound Network Connection Initiated By Cmstp.EXE · sigma-rule
- Outbound Network Connection Initiated By Microsoft Dialer · sigma-rule
- Outbound Network Connection Initiated By Script Interpreter · sigma-rule
- Outbound RDP Connections Over Non-Standard Tools · sigma-rule
- Outdated Dependency Or Vulnerability Alert Disabled · sigma-rule
- Outlook EnableUnsafeClientMailRules Setting Enabled · sigma-rule
- Outlook EnableUnsafeClientMailRules Setting Enabled - Registry · sigma-rule
- Outlook Macro Execution Without Warning Setting Enabled · sigma-rule
- Password Change on Directory Service Restore Mode (DSRM) Account · sigma-rule
- Password Dumper Activity on LSASS · sigma-rule
- Password Dumper Remote Thread in LSASS · sigma-rule
- Password Protected ZIP File Opened (Email Attachment) · sigma-rule
- Password Protected ZIP File Opened (Suspicious Filenames) · sigma-rule
- Password Spray Activity · sigma-rule
- PCRE.NET Package Image Load · sigma-rule
- PCRE.NET Package Temp Files · sigma-rule
- Persistence and Execution at Scale via GPO Scheduled Task · sigma-rule
- PetitPotam Suspicious Kerberos TGT Request · sigma-rule
- Phishing Pattern ISO in Archive · sigma-rule
- PIM Alert Setting Changes To Disabled · sigma-rule
- PIM Approvals And Deny Elevation · sigma-rule
- Ping Hex IP · sigma-rule
- Possible DCSync Attack · sigma-rule
- Possible Impacket SecretDump Remote Activity · sigma-rule
- Possible Impacket SecretDump Remote Activity - Zeek · sigma-rule
- Possible PetitPotam Coerce Authentication Attempt · sigma-rule
- Possible Privilege Escalation via Weak Service Permissions · sigma-rule
- Possible Shadow Credentials Added · sigma-rule
- Potential Adplus.EXE Abuse · sigma-rule
- Potential AMSI Bypass Via .NET Reflection · sigma-rule
- Potential AMSI COM Server Hijacking · sigma-rule
- Potential appverifUI.DLL Sideloading · sigma-rule
- Potential Arbitrary Code Execution Via Node.EXE · sigma-rule
- Potential Arbitrary Command Execution Using Msdt.EXE · sigma-rule
- Potential Arbitrary File Download Using Office Application · sigma-rule
- Potential AutoLogger Sessions Tampering · sigma-rule
- Potential Base64 Decoded From Images · sigma-rule
- Potential ClickFix Execution Pattern - Registry · sigma-rule
- Potential CobaltStrike Process Patterns · sigma-rule
- Potential CobaltStrike Service Installations - Registry · sigma-rule
- Potential CommandLine Obfuscation Using Unicode Characters From Suspicious Image · sigma-rule
- Potential CommandLine Path Traversal Via Cmd.EXE · sigma-rule
- Potential Credential Dumping Attempt Using New NetworkProvider - CLI · sigma-rule
- Potential Credential Dumping Attempt Via PowerShell Remote Thread · sigma-rule
- Potential Credential Dumping Via WER · sigma-rule
- Potential Crypto Mining Activity · sigma-rule
- Potential Data Exfiltration Activity Via CommandLine Tools · sigma-rule
- Potential Data Stealing Via Chromium Headless Debugging · sigma-rule
- Potential Defense Evasion Via Rename Of Highly Relevant Binaries · sigma-rule
- Potential Defense Evasion Via Right-to-Left Override · sigma-rule
- Potential DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE · sigma-rule
- Potential DLL Sideloading Of Non-Existent DLLs From System Folders · sigma-rule
- Potential DLL Sideloading Via comctl32.dll · sigma-rule
- Potential DLL Sideloading Via VMware Xfer · sigma-rule
- Potential EACore.DLL Sideloading · sigma-rule
- Potential Edputil.DLL Sideloading · sigma-rule
- Potential EventLog File Location Tampering · sigma-rule
- Potential Excel.EXE DCOM Lateral Movement Via ActivateMicrosoftApp · sigma-rule
- Potential File Extension Spoofing Using Right-to-Left Override · sigma-rule
- Potential File Overwrite Via Sysinternals SDelete · sigma-rule
- Potential GobRAT File Discovery Via Grep · sigma-rule
- Potential Invoke-Mimikatz PowerShell Script · sigma-rule
- Potential Iviewers.DLL Sideloading · sigma-rule
- Potential JLI.dll Side-Loading · sigma-rule
- Potential JNDI Injection Exploitation In JVM Based Application · sigma-rule
- Potential Kerberos Coercion by Spoofing SPNs via DNS Manipulation · sigma-rule
- Potential LethalHTA Technique Execution · sigma-rule
- Potential Local File Read Vulnerability In JVM Based Application · sigma-rule
- Potential LSASS Process Dump Via Procdump · sigma-rule
- Potential Malicious Usage of CloudTrail System Manager · sigma-rule
- Potential Manage-bde.wsf Abuse To Proxy Execution · sigma-rule
- Potential Meterpreter/CobaltStrike Activity · sigma-rule
- Potential MFA Bypass Using Legacy Client Authentication · sigma-rule
- Potential Mpclient.DLL Sideloading · sigma-rule
- Potential Mpclient.DLL Sideloading Via Defender Binaries · sigma-rule
- Potential MsiExec Masquerading · sigma-rule
- Potential MSTSC Shadowing Activity · sigma-rule
- Potential Netcat Reverse Shell Execution · sigma-rule
- Potential NTLM Coercion Via Certutil.EXE · sigma-rule
- Potential OGNL Injection Exploitation In JVM Based Application · sigma-rule
- Potential Okta Password in AlternateID Field · sigma-rule
- Potential Persistence Via App Paths Default Property · sigma-rule
- Potential Persistence Via Excel Add-in - Registry · sigma-rule
- Potential Persistence Via GlobalFlags · sigma-rule
- Potential Persistence Via Logon Scripts - CommandLine · sigma-rule
- Potential Persistence Via Microsoft Office Add-In · sigma-rule
- Potential Persistence Via Microsoft Office Startup Folder · sigma-rule
- Potential Persistence Via Outlook Form · sigma-rule
- Potential Persistence Via Outlook Home Page · sigma-rule
- Potential Persistence Via Outlook LoadMacroProviderOnBoot Setting · sigma-rule
- Potential Persistence Via Outlook Today Page · sigma-rule
- Potential Persistence Via PlistBuddy · sigma-rule
- Potential Persistence Via Powershell Search Order Hijacking - Task · sigma-rule
- Potential Persistence Via Shim Database In Uncommon Location · sigma-rule
- Potential PowerShell Command Line Obfuscation · sigma-rule
- Potential PowerShell Execution Via DLL · sigma-rule
- Potential PowerShell Obfuscation Via Reversed Commands · sigma-rule
- Potential PowerShell Obfuscation Via WCHAR/CHAR · sigma-rule
- Potential Powershell ReverseShell Connection · sigma-rule
- Potential Privilege Escalation To LOCAL SYSTEM · sigma-rule
- Potential Privilege Escalation Using Symlink Between Osk and Cmd · sigma-rule
- Potential Privilege Escalation via Local Kerberos Relay over LDAP · sigma-rule
- Potential Privilege Escalation via Service Permissions Weakness · sigma-rule
- Potential Process Injection Via Msra.EXE · sigma-rule
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution · sigma-rule
- Potential Provisioning Registry Key Abuse For Binary Proxy Execution - REG · sigma-rule
- Potential PsExec Remote Execution · sigma-rule
- Potential PSFactoryBuffer COM Hijacking · sigma-rule
- Potential Qakbot Registry Activity · sigma-rule
- Potential Ransomware Activity Using LegalNotice Message · sigma-rule
- Potential Rcdll.DLL Sideloading · sigma-rule
- Potential RCE Exploitation Attempt In NodeJS · sigma-rule
- Potential RDP Tunneling Via Plink · sigma-rule
- Potential RDP Tunneling Via SSH · sigma-rule
- Potential Reconnaissance For Cached Credentials Via Cmdkey.EXE · sigma-rule
- Potential Registry Persistence Attempt Via Windows Telemetry · sigma-rule
- Potential Remote PowerShell Session Initiated · sigma-rule
- Potential Remote SquiblyTwo Technique Execution · sigma-rule
- Potential RemoteFXvGPUDisablement.EXE Abuse · sigma-rule
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell Module · sigma-rule
- Potential RemoteFXvGPUDisablement.EXE Abuse - PowerShell ScriptBlock · sigma-rule
- Potential RipZip Attack on Startup Folder · sigma-rule
- Potential RjvPlatform.DLL Sideloading From Non-Default Location · sigma-rule
- Potential Rundll32 Execution With DLL Stored In ADS · sigma-rule
- Potential SAM Database Dump · sigma-rule
- Potential Server Side Template Injection In Velocity · sigma-rule
- Potential SmadHook.DLL Sideloading · sigma-rule
- Potential SpEL Injection In Spring Framework · sigma-rule
- Potential SSH Tunnel Persistence Install Using A Scheduled Task · sigma-rule
- Potential Startup Shortcut Persistence Via PowerShell.EXE · sigma-rule
- Potential Suspicious Mofcomp Execution · sigma-rule
- Potential SysInternals ProcDump Evasion · sigma-rule
- Potential System DLL Sideloading From Non System Locations · sigma-rule
- Potential Tampering With RDP Related Registry Keys Via Reg.EXE · sigma-rule
- Potential Tampering With Security Products Via WMIC · sigma-rule
- Potential Vcruntime140 DLL Sideloading · sigma-rule
- Potential Waveedit.DLL Sideloading · sigma-rule
- Potential WerFault ReflectDebugger Registry Value Abuse · sigma-rule
- Potential WinAPI Calls Via CommandLine · sigma-rule
- Potential WinAPI Calls Via PowerShell Scripts · sigma-rule
- Potential Windows Defender AV Bypass Via Dump64.EXE Rename · sigma-rule
- Potential Windows Defender Tampering Via Wmic.EXE · sigma-rule
- Potential Winnti Dropper Activity · sigma-rule
- Potential XXE Exploitation Attempt In JVM Based Application · sigma-rule
- Potentially Suspicious ASP.NET Compilation Via AspNetCompiler · sigma-rule
- Potentially Suspicious Child Process Of Regsvr32 · sigma-rule
- Potentially Suspicious Child Processes Spawned by ConHost · sigma-rule
- Potentially Suspicious Command Executed Via Run Dialog Box - Registry · sigma-rule
- Potentially Suspicious DLL Registered Via Odbcconf.EXE · sigma-rule
- Potentially Suspicious Event Viewer Child Process · sigma-rule
- Potentially Suspicious Execution From Parent Process In Public Folder · sigma-rule
- Potentially Suspicious Malware Callback Communication · sigma-rule
- Potentially Suspicious Malware Callback Communication - Linux · sigma-rule
- Potentially Suspicious ODBC Driver Registered · sigma-rule
- Potentially Suspicious Office Document Executed From Trusted Location · sigma-rule
- Potentially Suspicious Regsvr32 HTTP IP Pattern · sigma-rule
- Powershell Add Name Resolution Policy Table Rule · sigma-rule
- PowerShell ADRecon Execution · sigma-rule
- PowerShell as a Service in Registry · sigma-rule
- PowerShell Base64 Encoded FromBase64String Cmdlet · sigma-rule
- PowerShell Base64 Encoded IEX Cmdlet · sigma-rule
- PowerShell Base64 Encoded Invoke Keyword · sigma-rule
- Powershell Base64 Encoded MpPreference Cmdlet · sigma-rule
- PowerShell Base64 Encoded Reflective Assembly Load · sigma-rule
- PowerShell Base64 Encoded WMI Classes · sigma-rule
- PowerShell Called from an Executable Version Mismatch · sigma-rule
- PowerShell Credential Prompt · sigma-rule
- Powershell Defender Disable Scan Feature · sigma-rule
- PowerShell Defender Threat Severity Default Action Set to 'Allow' or 'NoAction' · sigma-rule
- Powershell DNSExfiltration · sigma-rule
- PowerShell Download and Execution Cradles · sigma-rule
- PowerShell Get-Process LSASS · sigma-rule
- PowerShell Get-Process LSASS in ScriptBlock · sigma-rule
- Powershell Install a DLL in System Directory · sigma-rule
- PowerShell Logging Disabled Via Registry Key Tampering · sigma-rule
- PowerShell PSAttack · sigma-rule
- PowerShell SAM Copy · sigma-rule
- PowerShell Scripts Installed as Services · sigma-rule
- PowerShell Scripts Installed as Services - Security · sigma-rule
- PowerShell Set-Acl On Windows Folder - PsScript · sigma-rule
- PowerShell ShellCode · sigma-rule
- Powershell Token Obfuscation - Process Creation · sigma-rule
- PowerShell Web Access Feature Enabled Via DISM · sigma-rule
- PowerShell Web Access Installation - PsScript · sigma-rule
- Powerview Add-DomainObjectAcl DCSync AD Extend Right · sigma-rule
- PowerView PowerShell Cmdlets - ScriptBlock · sigma-rule
- PPL Tampering Via WerFaultSecure · sigma-rule
- Prefetch File Deleted · sigma-rule
- Primary Refresh Token Access Attempt · sigma-rule
- PrintBrm ZIP Creation of Extraction · sigma-rule
- Privilege Escalation via Named Pipe Impersonation · sigma-rule
- Privileged User Has Been Created · sigma-rule
- Process Access via TrolleyExpress Exclusion · sigma-rule
- Process Execution Error In JVM Based Application · sigma-rule
- Process Execution From A Potentially Suspicious Folder · sigma-rule
- Process Execution From Shared Memory Directory · sigma-rule
- Process Explorer Driver Creation By Non-Sysinternals Binary · sigma-rule
- Process Initiated Network Connection To Ngrok Domain · sigma-rule
- Process Memory Dump Via Comsvcs.DLL · sigma-rule
- Process Memory Dump via RdrLeakDiag.EXE · sigma-rule
- ProcessHacker Privilege Elevation · sigma-rule
- Protected Storage Service Access · sigma-rule
- Proxy Execution Via Wuauclt.EXE · sigma-rule
- PSAsyncShell - Asynchronous TCP Reverse Shell · sigma-rule
- PSExec and WMI Process Creations Block · sigma-rule
- PSEXEC Remote Execution File Artefact · sigma-rule
- PsExec/PAExec Escalation to LOCAL SYSTEM · sigma-rule
- PUA - 3Proxy Execution · sigma-rule
- PUA - AdFind Suspicious Execution · sigma-rule
- PUA - AdvancedRun Suspicious Execution · sigma-rule
- PUA - Chisel Tunneling Tool Execution · sigma-rule
- PUA - CleanWipe Execution · sigma-rule
- PUA - Crassus Execution · sigma-rule
- PUA - CsExec Execution · sigma-rule
- PUA - DefenderCheck Execution · sigma-rule
- PUA - DIT Snapshot Viewer · sigma-rule
- PUA - Fast Reverse Proxy (FRP) Execution · sigma-rule
- PUA - Kernel Driver Utility (KDU) Execution · sigma-rule
- PUA - Memory Dump Mount Via MemProcFS · sigma-rule
- PUA - Netcat Suspicious Execution · sigma-rule
- PUA - Ngrok Execution · sigma-rule
- PUA - Nimgrab Execution · sigma-rule
- PUA - NirCmd Execution As LOCAL SYSTEM · sigma-rule
- PUA - NPS Tunneling Tool Execution · sigma-rule
- PUA - NSudo Execution · sigma-rule
- PUA - PingCastle Execution From Potentially Suspicious Parent · sigma-rule
- PUA - Process Hacker Driver Load · sigma-rule
- PUA - Rclone Execution · sigma-rule
- PUA - Restic Backup Tool Execution · sigma-rule
- PUA - RunXCmd Execution · sigma-rule
- PUA - Seatbelt Execution · sigma-rule
- PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE · sigma-rule
- PUA - Wsudo Suspicious Execution · sigma-rule
- PUA- IOX Tunneling Tool Execution · sigma-rule
- Publicly Accessible RDP Service · sigma-rule
- Python Function Execution Security Warning Disabled In Excel · sigma-rule
- Python Function Execution Security Warning Disabled In Excel - Registry · sigma-rule
- Python One-Liners with Base64 Decoding · sigma-rule
- Python One-Liners with Base64 Decoding - Linux · sigma-rule
- Python Spawning Pretty TTY on Windows · sigma-rule
- Query Tor Onion Address - DNS Client · sigma-rule
- Raccine Uninstall · sigma-rule
- Rar Usage with Password and Compression Level · sigma-rule
- Rare Remote Thread Creation By Uncommon Source Image · sigma-rule
- Raw Paste Service Access · sigma-rule
- RDP Connection Allowed Via Netsh.EXE · sigma-rule
- RDP Login from Localhost · sigma-rule
- RDP Over Reverse SSH Tunnel · sigma-rule
- RDP over Reverse SSH Tunnel WFP · sigma-rule
- RDP Port Forwarding Rule Added Via Netsh.EXE · sigma-rule
- RDP Sensitive Settings Changed · sigma-rule
- RDP to HTTP or HTTPS Target Ports · sigma-rule
- Reconnaissance Activity · sigma-rule
- RedMimicry Winnti Playbook Registry Manipulation · sigma-rule
- Reg Add Suspicious Paths · sigma-rule
- Regedit as Trusted Installer · sigma-rule
- Register new Logon Process by Rubeus · sigma-rule
- Registry Disable System Restore · sigma-rule
- Registry Export of Third-Party Credentials · sigma-rule
- Registry Modification for OCI DLL Redirection · sigma-rule
- Registry Persistence Mechanisms in Recycle Bin · sigma-rule
- Registry Persistence via Explorer Run Key · sigma-rule
- Registry Persistence via Service in Safe Mode · sigma-rule
- Regsvr32 DLL Execution With Suspicious File Extension · sigma-rule
- Regsvr32 Execution From Highly Suspicious Location · sigma-rule
- Relevant Anti-Virus Signature Keywords In Application Log · sigma-rule
- Relevant ClamAV Message · sigma-rule
- Remote Access Tool - Anydesk Execution From Suspicious Folder · sigma-rule
- Remote Access Tool - AnyDesk Silent Installation · sigma-rule
- Remote Access Tool - Renamed MeshAgent Execution - MacOS · sigma-rule
- Remote Access Tool - Renamed MeshAgent Execution - Windows · sigma-rule
- Remote Access Tool - ScreenConnect Server Web Shell Execution · sigma-rule
- Remote CHM File Download/Execution Via HH.EXE · sigma-rule
- Remote DCOM/WMI Lateral Movement · sigma-rule
- Remote LSASS Process Access Through Windows Remote Management · sigma-rule
- Remote PowerShell Session (PS Module) · sigma-rule
- Remote PowerShell Sessions Network Connections (WinRM) · sigma-rule
- Remote Registry Lateral Movement · sigma-rule
- Remote Schedule Task Lateral Movement via ATSvc · sigma-rule
- Remote Schedule Task Lateral Movement via ITaskSchedulerService · sigma-rule
- Remote Schedule Task Lateral Movement via SASec · sigma-rule
- Remote Server Service Abuse for Lateral Movement · sigma-rule
- Remote Thread Created In KeePass.EXE · sigma-rule
- Remote Thread Creation Ttdinject.exe Proxy · sigma-rule
- Remote XSL Execution Via Msxsl.EXE · sigma-rule
- RemoteFXvGPUDisablement Abuse Via AtomicTestHarnesses · sigma-rule
- Remotely Hosted HTA File Executed Via Mshta.EXE · sigma-rule
- Removal Of AMSI Provider Registry Keys · sigma-rule
- Remove Exported Mailbox from Exchange Webserver · sigma-rule
- Renamed AdFind Execution · sigma-rule
- Renamed AutoIt Execution · sigma-rule
- Renamed BrowserCore.EXE Execution · sigma-rule
- Renamed Cloudflared.EXE Execution · sigma-rule
- Renamed CreateDump Utility Execution · sigma-rule
- Renamed Gpg.EXE Execution · sigma-rule
- Renamed Jusched.EXE Execution · sigma-rule
- Renamed Mavinject.EXE Execution · sigma-rule
- Renamed MegaSync Execution · sigma-rule
- Renamed Msdt.EXE Execution · sigma-rule
- Renamed NirCmd.EXE Execution · sigma-rule
- Renamed Office Binary Execution · sigma-rule
- Renamed PAExec Execution · sigma-rule
- Renamed PingCastle Binary Execution · sigma-rule
- Renamed Plink Execution · sigma-rule
- Renamed ProcDump Execution · sigma-rule
- Renamed Schtasks Execution · sigma-rule
- Renamed SysInternals DebugView Execution · sigma-rule
- Renamed Sysinternals Sdelete Execution · sigma-rule
- Renamed Visual Studio Code Tunnel Execution · sigma-rule
- Renamed Vmnat.exe Execution · sigma-rule
- Renamed ZOHO Dctask64 Execution · sigma-rule
- Replay Attack Detected · sigma-rule
- Restore Public AWS RDS Instance · sigma-rule
- Restricted Software Access By SRP · sigma-rule
- RestrictedAdminMode Registry Value Tampering · sigma-rule
- RestrictedAdminMode Registry Value Tampering - ProcCreation · sigma-rule
- Roles Activated Too Frequently · sigma-rule
- Roles Activation Doesn't Require MFA · sigma-rule
- Roles Are Not Being Used · sigma-rule
- Roles Assigned Outside PIM · sigma-rule
- Root Certificate Installed From Susp Locations · sigma-rule
- RottenPotato Like Attack Pattern · sigma-rule
- Run PowerShell Script from ADS · sigma-rule
- Run PowerShell Script from Redirected Input Stream · sigma-rule
- Rundll32 Execution Without CommandLine Parameters · sigma-rule
- Rundll32 Execution Without Parameters · sigma-rule
- Rundll32 Registered COM Objects · sigma-rule
- RunDLL32 Spawning Explorer · sigma-rule
- Rundll32 UNC Path Execution · sigma-rule
- RunMRU Registry Key Deletion · sigma-rule
- RunMRU Registry Key Deletion - Registry · sigma-rule
- Running Chrome VPN Extensions via the Registry 2 VPN Extension · sigma-rule
- SafeBoot Registry Key Deleted Via Reg.EXE · sigma-rule
- SAM Registry Hive Handle Request · sigma-rule
- SAML Token Issuer Anomaly · sigma-rule
- Scheduled Task Creation Masquerading as System Processes · sigma-rule
- Scheduled Task Executing Encoded Payload from Registry · sigma-rule
- Scheduled TaskCache Change by Uncommon Program · sigma-rule
- Schtasks Creation Or Modification With SYSTEM Privileges · sigma-rule
- Schtasks From Suspicious Folders · sigma-rule
- Script Event Consumer Spawning Process · sigma-rule
- Script Interpreter Execution From Suspicious Folder · sigma-rule
- Script Interpreter Spawning Credential Scanner - Linux · sigma-rule
- Script Interpreter Spawning Credential Scanner - Windows · sigma-rule
- Sdiagnhost Calling Suspicious Child Process · sigma-rule
- Security Event Logging Disabled via MiniNt Registry Key - Process · sigma-rule
- Security Event Logging Disabled via MiniNt Registry Key - Registry Set · sigma-rule
- Security Eventlog Cleared · sigma-rule
- Security Privileges Enumeration Via Whoami.EXE · sigma-rule
- Security Service Disabled Via Reg.EXE · sigma-rule
- Security Support Provider (SSP) Added to LSA Configuration · sigma-rule
- Self Extracting Package Creation Via Iexpress.EXE From Potentially Suspicious Location · sigma-rule
- Sensitive File Access Via Volume Shadow Copy Backup · sigma-rule
- Sensitive File Dump Via Print.EXE · sigma-rule
- Sensitive File Dump Via Wbadmin.EXE · sigma-rule
- Sensitive File Recovery From Backup Via Wbadmin.EXE · sigma-rule
- Server Side Template Injection Strings · sigma-rule
- Service Binary in Suspicious Folder · sigma-rule
- Service DACL Abuse To Hide Services Via Sc.EXE · sigma-rule
- Service Installation with Suspicious Folder Pattern · sigma-rule
- Service Installed By Unusual Client - Security · sigma-rule
- Service Installed By Unusual Client - System · sigma-rule
- Service Registry Key Deleted Via Reg.EXE · sigma-rule
- Set Suspicious Files as System Files Using Attrib.EXE · sigma-rule
- Shadow Copies Deletion Using Operating Systems Utilities · sigma-rule
- SharpHound Recon Account Discovery · sigma-rule
- SharpHound Recon Sessions · sigma-rule
- Shell Execution GCC - Linux · sigma-rule
- Shell Execution via Find - Linux · sigma-rule
- Shell Execution via Flock - Linux · sigma-rule
- Shell Execution via Git - Linux · sigma-rule
- Shell Execution via Nice - Linux · sigma-rule
- Shell Execution via Rsync - Linux · sigma-rule
- Shell Invocation via Env Command - Linux · sigma-rule
- Shell Invocation Via Ssh - Linux · sigma-rule
- Shell Open Registry Keys Manipulation · sigma-rule
- Shell32 DLL Execution in Suspicious Directory · sigma-rule
- Shellshock Expression · sigma-rule
- ShimCache Flush · sigma-rule
- Sign-in Failure Due to Conditional Access Requirements Not Met · sigma-rule
- Sign-In From Malware Infected IP · sigma-rule
- Sign-ins from Non-Compliant Devices · sigma-rule
- Silenttrinity Stager Msbuild Activity · sigma-rule
- Sliver C2 Default Service Installation · sigma-rule
- SMB Create Remote File Admin Share · sigma-rule
- smbexec.py Service Installation · sigma-rule
- SQL Injection Strings In URI · sigma-rule
- SQLite Chromium Profile Data DB Access · sigma-rule
- SQLite Firefox Profile Data DB Access · sigma-rule
- Stale Accounts In A Privileged Role · sigma-rule
- Successful Overpass the Hash Attempt · sigma-rule
- Suspect Svchost Activity · sigma-rule
- Suspicious Active Directory Database Snapshot Via ADExplorer · sigma-rule
- Suspicious Activity in Shell Commands · sigma-rule
- Suspicious AddinUtil.EXE CommandLine Execution · sigma-rule
- Suspicious AgentExecutor PowerShell Execution · sigma-rule
- Suspicious Application Allowed Through Exploit Guard · sigma-rule
- Suspicious ArcSOC.exe Child Process · sigma-rule
- Suspicious ASPX File Drop by Exchange · sigma-rule
- Suspicious Autorun Registry Modified via WMI · sigma-rule
- Suspicious Binaries and Scripts in Public Folder · sigma-rule
- Suspicious Binary In User Directory Spawned From Office Application · sigma-rule
- Suspicious Binary Writes Via AnyDesk · sigma-rule
- Suspicious BitLocker Access Agent Update Utility Execution · sigma-rule
- Suspicious Browser Activity · sigma-rule
- Suspicious Calculator Usage · sigma-rule
- Suspicious Camera and Microphone Access · sigma-rule
- Suspicious CertReq Command to Download · sigma-rule
- Suspicious Child Process Created as System · sigma-rule
- Suspicious Child Process of AspNetCompiler · sigma-rule
- Suspicious Child Process Of BgInfo.EXE · sigma-rule
- Suspicious Child Process Of Manage Engine ServiceDesk · sigma-rule
- Suspicious Child Process of Notepad++ Updater - GUP.Exe · sigma-rule
- Suspicious Child Process Of SQL Server · sigma-rule
- Suspicious Child Process Of Wermgr.EXE · sigma-rule
- Suspicious Chromium Browser Instance Executed With Custom Extension · sigma-rule
- Suspicious ClickFix/FileFix Execution Pattern · sigma-rule
- Suspicious Command Patterns In Scheduled Task Creation · sigma-rule
- Suspicious Control Panel DLL Load · sigma-rule
- Suspicious Creation with Colorcpl · sigma-rule
- Suspicious Curl.EXE Download · sigma-rule
- Suspicious CustomShellHost Execution · sigma-rule
- Suspicious Debugger Registration Cmdline · sigma-rule
- Suspicious Desktopimgdownldr Command · sigma-rule
- Suspicious Desktopimgdownldr Target File · sigma-rule
- Suspicious DLL Loaded via CertOC.EXE · sigma-rule
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing · sigma-rule
- Suspicious DNS Query Indicating Kerberos Coercion via DNS Object SPN Spoofing - Network · sigma-rule
- Suspicious DotNET CLR Usage Log Artifact · sigma-rule
- Suspicious Double Extension File Execution · sigma-rule
- Suspicious Double Extension Files · sigma-rule
- Suspicious Download and Execute Pattern via Curl/Wget · sigma-rule
- Suspicious Download From Direct IP Via Bitsadmin · sigma-rule
- Suspicious Download From File-Sharing Website Via Bitsadmin · sigma-rule
- Suspicious Download from Office Domain · sigma-rule
- Suspicious Driver/DLL Installation Via Odbcconf.EXE · sigma-rule
- Suspicious Dropbox API Usage · sigma-rule
- Suspicious DumpMinitool Execution · sigma-rule
- Suspicious Encoded And Obfuscated Reflection Assembly Load Function Call · sigma-rule
- Suspicious Encoded PowerShell Command Line · sigma-rule
- Suspicious Encoded Scripts in a WMI Consumer · sigma-rule
- Suspicious Eventlog Clearing or Configuration Change Activity · sigma-rule
- Suspicious Executable File Creation · sigma-rule
- Suspicious Execution From Outlook Temporary Folder · sigma-rule
- Suspicious Execution Of Renamed Sysinternals Tools - Registry · sigma-rule
- Suspicious Explorer Process with Whitespace Padding - ClickFix/FileFix · sigma-rule
- Suspicious External WebDAV Execution · sigma-rule
- Suspicious File Created by ArcSOC.exe · sigma-rule
- Suspicious File Created in Outlook Temporary Directory · sigma-rule
- Suspicious File Download From File Sharing Websites - File Stream · sigma-rule
- Suspicious File Downloaded From Direct IP Via Certutil.EXE · sigma-rule
- Suspicious File Downloaded From File-Sharing Website Via Certutil.EXE · sigma-rule
- Suspicious File Encoded To Base64 Via Certutil.EXE · sigma-rule
- Suspicious File Execution From Internet Hosted WebDav Share · sigma-rule
- Suspicious File Write to SharePoint Layouts Directory · sigma-rule
- Suspicious FileFix Execution Pattern · sigma-rule
- Suspicious Filename with Embedded Base64 Commands · sigma-rule
- Suspicious Get-ADDBAccount Usage · sigma-rule
- Suspicious Get-Variable.exe Creation · sigma-rule
- Suspicious Greedy Compression Using Rar.EXE · sigma-rule
- Suspicious GrpConv Execution · sigma-rule
- Suspicious GUP Usage · sigma-rule
- Suspicious HH.EXE Execution · sigma-rule
- Suspicious HWP Sub Processes · sigma-rule
- Suspicious IIS Module Registration · sigma-rule
- Suspicious Inbox Forwarding Identity Protection · sigma-rule
- Suspicious Inbox Manipulation Rules · sigma-rule
- Suspicious Interactive PowerShell as SYSTEM · sigma-rule
- Suspicious Invocation of Shell via AWK - Linux · sigma-rule
- Suspicious Invocation of Shell via Rsync · sigma-rule
- Suspicious Invoke-WebRequest Execution · sigma-rule
- Suspicious Java Children Processes · sigma-rule
- Suspicious JavaScript Execution Via Mshta.EXE · sigma-rule
- Suspicious Kerberos Ticket Request via CLI · sigma-rule
- Suspicious Kerberos Ticket Request via PowerShell Script - ScriptBlock · sigma-rule
- Suspicious Kernel Dump Using Dtrace · sigma-rule
- Suspicious Key Manager Access · sigma-rule
- Suspicious LDAP-Attributes Used · sigma-rule
- Suspicious LNK Command-Line Padding with Whitespace Characters · sigma-rule
- Suspicious Loading of Dbgcore/Dbghelp DLLs from Uncommon Location · sigma-rule
- Suspicious LSASS Access Via MalSecLogon · sigma-rule
- Suspicious Manipulation Of Default Accounts Via Net.EXE · sigma-rule
- Suspicious Microsoft Office Child Process · sigma-rule
- Suspicious Microsoft Office Child Process - MacOS · sigma-rule
- Suspicious Microsoft OneNote Child Process · sigma-rule
- Suspicious Modification Of Scheduled Tasks · sigma-rule
- Suspicious MSDT Parent Process · sigma-rule
- Suspicious MSExchangeMailboxReplication ASPX Write · sigma-rule
- Suspicious MSHTA Child Process · sigma-rule
- Suspicious Mshta.EXE Execution Patterns · sigma-rule
- Suspicious Mstsc.EXE Execution With Local RDP File · sigma-rule
- Suspicious Named Error · sigma-rule
- Suspicious New Service Creation · sigma-rule
- Suspicious NTLM Authentication on the Printer Spooler Service · sigma-rule
- Suspicious Outlook Child Process · sigma-rule
- Suspicious Outlook Macro Created · sigma-rule
- Suspicious Parent Double Extension File Execution · sigma-rule
- Suspicious Path In Keyboard Layout IME File Registry Value · sigma-rule
- Suspicious Persistence Via VMwareToolBoxCmd.EXE VM State Change Script · sigma-rule
- Suspicious Ping/Del Command Combination · sigma-rule
- Suspicious Plink Port Forwarding · sigma-rule
- Suspicious PowerShell Download and Execute Pattern · sigma-rule
- Suspicious PowerShell Encoded Command Patterns · sigma-rule
- Suspicious PowerShell IEX Execution Patterns · sigma-rule
- Suspicious PowerShell Invocations - Generic · sigma-rule
- Suspicious PowerShell Invocations - Generic - PowerShell Module · sigma-rule
- Suspicious PowerShell Invocations - Specific · sigma-rule
- Suspicious PowerShell Invocations - Specific - PowerShell Module · sigma-rule
- Suspicious PowerShell Parameter Substring · sigma-rule
- Suspicious PowerShell Parent Process · sigma-rule
- Suspicious Printer Driver Empty Manufacturer · sigma-rule
- Suspicious Process Access of MsMpEng by WerFaultSecure - EDR-Freeze · sigma-rule
- Suspicious Process Access to LSASS with Dbgcore/Dbghelp DLLs · sigma-rule
- Suspicious Process By Web Server Process · sigma-rule
- Suspicious Process Created Via Wmic.EXE · sigma-rule
- Suspicious Process Masquerading As SvcHost.EXE · sigma-rule
- Suspicious Process Parents · sigma-rule
- Suspicious Process Patterns NTDS.DIT Exfil · sigma-rule
- Suspicious Processes Spawned by WinRM · sigma-rule
- Suspicious Program Location Whitelisted In Firewall Via Netsh.EXE · sigma-rule
- Suspicious Program Names · sigma-rule
- Suspicious Provlaunch.EXE Child Process · sigma-rule
- Suspicious PsExec Execution · sigma-rule
- Suspicious PsExec Execution - Zeek · sigma-rule
- Suspicious RDP Redirect Using TSCON · sigma-rule
- Suspicious Reconnaissance Activity Via GatherNetworkInfo.VBS · sigma-rule
- Suspicious Redirection to Local Admin Share · sigma-rule
- Suspicious Reg Add BitLocker · sigma-rule
- Suspicious Registry Modification From ADS Via Regini.EXE · sigma-rule
- Suspicious Regsvr32 Execution From Remote Share · sigma-rule
- Suspicious Remote Child Process From Outlook · sigma-rule
- Suspicious Renamed Comsvcs DLL Loaded By Rundll32 · sigma-rule
- Suspicious Response File Execution Via Odbcconf.EXE · sigma-rule
- Suspicious Reverse Shell Command Line · sigma-rule
- Suspicious Run Key from Download · sigma-rule
- Suspicious Rundll32 Activity Invoking Sys File · sigma-rule
- Suspicious Rundll32 Execution With Image Extension · sigma-rule
- Suspicious Rundll32 Invoking Inline VBScript · sigma-rule
- Suspicious Scheduled Task Creation · sigma-rule
- Suspicious Scheduled Task Creation Involving Temp Folder · sigma-rule
- Suspicious Scheduled Task Update · sigma-rule
- Suspicious Scheduled Task Write to System32 Tasks · sigma-rule
- Suspicious Schtasks Execution AppData Folder · sigma-rule
- Suspicious Schtasks Schedule Types · sigma-rule
- Suspicious Scripting in a WMI Consumer · sigma-rule
- Suspicious Serv-U Process Pattern · sigma-rule
- Suspicious Service Binary Directory · sigma-rule
- Suspicious Service DACL Modification Via Set-Service Cmdlet · sigma-rule
- Suspicious Service DACL Modification Via Set-Service Cmdlet - PS · sigma-rule
- Suspicious Service Installation · sigma-rule
- Suspicious Service Installation Script · sigma-rule
- Suspicious Service Path Modification · sigma-rule
- Suspicious ShellExec_RunDLL Call Via Ordinal · sigma-rule
- Suspicious Shim Database Patching Activity · sigma-rule
- Suspicious SignIns From A Non Registered Device · sigma-rule
- Suspicious Space Characters in RunMRU Registry Path - ClickFix · sigma-rule
- Suspicious Space Characters in TypedPaths Registry Path - FileFix · sigma-rule
- Suspicious Speech Runtime Binary Child Process · sigma-rule
- Suspicious Splwow64 Without Params · sigma-rule
- Suspicious Spool Service Child Process · sigma-rule
- Suspicious SQL Error Messages · sigma-rule
- Suspicious Startup Folder Persistence · sigma-rule
- Suspicious Svchost Process Access · sigma-rule
- Suspicious SYSTEM User Process Creation · sigma-rule
- Suspicious Teams Application Related ObjectAcess Event · sigma-rule
- Suspicious TSCON Start as SYSTEM · sigma-rule
- Suspicious UltraVNC Execution · sigma-rule
- Suspicious Uninstall of Windows Defender Feature via PowerShell · sigma-rule
- Suspicious Unsigned Dbghelp/Dbgcore DLL Loaded · sigma-rule
- Suspicious Unsigned Thor Scanner Execution · sigma-rule
- Suspicious Use of CSharp Interactive Console · sigma-rule
- Suspicious User Agent · sigma-rule
- Suspicious Velociraptor Child Process · sigma-rule
- Suspicious Volume Shadow Copy VSS_PS.dll Load · sigma-rule
- Suspicious Volume Shadow Copy Vssapi.dll Load · sigma-rule
- Suspicious WebDav Client Execution Via Rundll32.EXE · sigma-rule
- Suspicious Windows ANONYMOUS LOGON Local Account Created · sigma-rule
- Suspicious Windows Defender Registry Key Tampering Via Reg.EXE · sigma-rule
- Suspicious Windows Service Tampering · sigma-rule
- Suspicious Windows Strings In URI · sigma-rule
- Suspicious Windows Trace ETW Session Tamper Via Logman.EXE · sigma-rule
- Suspicious Windows Update Agent Empty Cmdline · sigma-rule
- Suspicious WMIC Execution Via Office Process · sigma-rule
- Suspicious WmiPrvSE Child Process · sigma-rule
- Symlink Etc Passwd · sigma-rule
- Sysinternals PsSuspend Suspicious Execution · sigma-rule
- SysKey Registry Keys Access · sigma-rule
- Syslog Clearing or Removal Via System Utilities · sigma-rule
- Sysmon Application Crashed · sigma-rule
- Sysmon Channel Reference Deletion · sigma-rule
- Sysmon Configuration Error · sigma-rule
- Sysmon Configuration Modification · sigma-rule
- Sysmon Discovery Via Default Driver Altitude Using Findstr.EXE · sigma-rule
- Sysmon Driver Altitude Change · sigma-rule
- Sysmon Driver Unloaded Via Fltmc.EXE · sigma-rule
- System Control Panel Item Loaded From Uncommon Location · sigma-rule
- System File Execution Location Anomaly · sigma-rule
- System Restore Registry Modification via CommandLine · sigma-rule
- T1047 Wmiprvse Wbemcomn DLL Hijack · sigma-rule
- Tamper Windows Defender - PSClassic · sigma-rule
- Tamper Windows Defender - ScriptBlockLogging · sigma-rule
- Tamper Windows Defender Remove-MpPreference · sigma-rule
- Tamper Windows Defender Remove-MpPreference - ScriptBlockLogging · sigma-rule
- Tamper With Sophos AV Registry Keys · sigma-rule
- Taskkill Symantec Endpoint Protection · sigma-rule
- Taskmgr as LOCAL_SYSTEM · sigma-rule
- Tasks Folder Evasion · sigma-rule
- Temporary Access Pass Added To An Account · sigma-rule
- Terminal Server Client Connection History Cleared - Registry · sigma-rule
- Terminal Service Process Spawn · sigma-rule
- Time Travel Debugging Utility Usage · sigma-rule
- Time Travel Debugging Utility Usage - Image · sigma-rule
- Too Many Global Admins · sigma-rule
- Tor Client/Browser Execution · sigma-rule
- Triple Cross eBPF Rootkit Default Persistence · sigma-rule
- Triple Cross eBPF Rootkit Install Commands · sigma-rule
- Trust Access Disable For VBApplications · sigma-rule
- Trusted Path Bypass via Windows Directory Spoofing · sigma-rule
- UAC Bypass Abusing Winsat Path Parsing - File · sigma-rule
- UAC Bypass Abusing Winsat Path Parsing - Process · sigma-rule
- UAC Bypass Abusing Winsat Path Parsing - Registry · sigma-rule
- UAC Bypass Tools Using ComputerDefaults · sigma-rule
- UAC Bypass Using .NET Code Profiler on MMC · sigma-rule
- UAC Bypass Using ChangePK and SLUI · sigma-rule
- UAC Bypass Using Consent and Comctl32 - File · sigma-rule
- UAC Bypass Using Consent and Comctl32 - Process · sigma-rule
- UAC Bypass Using Disk Cleanup · sigma-rule
- UAC Bypass Using DismHost · sigma-rule
- UAC Bypass Using IDiagnostic Profile · sigma-rule
- UAC Bypass Using IDiagnostic Profile - File · sigma-rule
- UAC Bypass Using IEInstal - File · sigma-rule
- UAC Bypass Using IEInstal - Process · sigma-rule
- UAC Bypass Using Iscsicpl - ImageLoad · sigma-rule
- UAC Bypass Using MSConfig Token Modification - File · sigma-rule
- UAC Bypass Using MSConfig Token Modification - Process · sigma-rule
- UAC Bypass Using NTFS Reparse Point - File · sigma-rule
- UAC Bypass Using NTFS Reparse Point - Process · sigma-rule
- UAC Bypass Using PkgMgr and DISM · sigma-rule
- UAC Bypass Using Windows Media Player - File · sigma-rule
- UAC Bypass Using Windows Media Player - Process · sigma-rule
- UAC Bypass Using Windows Media Player - Registry · sigma-rule
- UAC Bypass Using WOW64 Logger DLL Hijack · sigma-rule
- UAC Bypass via Event Viewer · sigma-rule
- UAC Bypass via ICMLuaUtil · sigma-rule
- UAC Bypass via Sdclt · sigma-rule
- UAC Bypass Via Wsreset · sigma-rule
- UAC Bypass With Fake DLL · sigma-rule
- UAC Bypass WSReset · sigma-rule
- UEFI Persistence Via Wpbbin - FileCreation · sigma-rule
- UEFI Persistence Via Wpbbin - ProcessCreation · sigma-rule
- Uncommon Child Process Of Setres.EXE · sigma-rule
- Uncommon Extension In Keyboard Layout IME File Registry Value · sigma-rule
- Uncommon File Created by Notepad++ Updater Gup.EXE · sigma-rule
- Uncommon File Created In Office Startup Folder · sigma-rule
- Uncommon Microsoft Office Trusted Location Added · sigma-rule
- Uncommon Network Connection Initiated By Certutil.EXE · sigma-rule
- Uncommon One Time Only Scheduled Task At 00:00 · sigma-rule
- Uncommon Svchost Command Line Parameter · sigma-rule
- Uncommon Userinit Child Process · sigma-rule
- Unfamiliar Sign-In Properties · sigma-rule
- Uninstall Crowdstrike Falcon Sensor · sigma-rule
- Uninstall Sysinternals Sysmon · sigma-rule
- Unsigned Binary Loaded From Suspicious Location · sigma-rule
- Unsigned Mfdetours.DLL Sideloading · sigma-rule
- Unusual Child Process of dns.exe · sigma-rule
- Unusual File Deletion by Dns.exe · sigma-rule
- Unusual File Download from Direct IP Address · sigma-rule
- Unusual File Modification by dns.exe · sigma-rule
- Usage of Renamed Sysinternals Tools - RegistrySet · sigma-rule
- Use of Legacy Authentication Protocols · sigma-rule
- Use of W32tm as Timer · sigma-rule
- User Added To Highly Privileged Group · sigma-rule
- User Added To Privilege Role · sigma-rule
- User Added to Remote Desktop Users Group · sigma-rule
- User Couldn't Call a Privileged Service 'LsaRegisterLogonProcess' · sigma-rule
- User Shell Folders Registry Modification via CommandLine · sigma-rule
- Users Added to Global or Device Admin Roles · sigma-rule
- Using SettingSyncHost.exe as LOLBin · sigma-rule
- VBA DLL Loaded Via Office Application · sigma-rule
- VBScript Payload Stored in Registry · sigma-rule
- VeeamBackup Database Credentials Dump Via Sqlcmd.EXE · sigma-rule
- Vim GTFOBin Abuse - Linux · sigma-rule
- Visual Basic Command Line Compiler Usage · sigma-rule
- VMMap Unsigned Dbghelp.DLL Potential Sideloading · sigma-rule
- VMToolsd Suspicious Child Process · sigma-rule
- VolumeShadowCopy Symlink Creation Via Mklink · sigma-rule
- Vulnerable Driver Blocklist Registry Tampering Via CommandLine · sigma-rule
- Vulnerable Driver Load · sigma-rule
- Vulnerable HackSys Extreme Vulnerable Driver Load · sigma-rule
- Vulnerable Netlogon Secure Channel Connection Allowed · sigma-rule
- Vulnerable WinRing0 Driver Load · sigma-rule
- Wannacry Killswitch Domain · sigma-rule
- Wdigest CredGuard Registry Modification · sigma-rule
- Wdigest Enable UseLogonCredential · sigma-rule
- Weak Encryption Enabled and Kerberoast · sigma-rule
- Webshell Detection With Command Line Keywords · sigma-rule
- Webshell Hacking Activity Patterns · sigma-rule
- Webshell ReGeorg Detection Via Web Logs · sigma-rule
- Webshell Tool Reconnaissance Activity · sigma-rule
- WerFault LSASS Process Memory Dump · sigma-rule
- WhoAmI as Parameter · sigma-rule
- Whoami.EXE Execution From Privileged Process · sigma-rule
- Win Defender Restored Quarantine File · sigma-rule
- WinDivert Driver Load · sigma-rule
- Windows AMSI Related Registry Tampering Via CommandLine · sigma-rule
- Windows Binaries Write Suspicious Extensions · sigma-rule
- Windows Credential Guard Disabled - Registry · sigma-rule
- Windows Credential Guard Registry Tampering Via CommandLine · sigma-rule
- Windows Credential Guard Related Registry Value Deleted - Registry · sigma-rule
- Windows Defender AMSI Trigger Detected · sigma-rule
- Windows Defender Configuration Changes · sigma-rule
- Windows Defender Context Menu Removed · sigma-rule
- Windows Defender Definition Files Removed · sigma-rule
- Windows Defender Exploit Guard Tamper · sigma-rule
- Windows Defender Grace Period Expired · sigma-rule
- Windows Defender Malware And PUA Scanning Disabled · sigma-rule
- Windows Defender Real-time Protection Disabled · sigma-rule
- Windows Defender Service Disabled - Registry · sigma-rule
- Windows Defender Threat Detected · sigma-rule
- Windows Defender Threat Severity Default Action Modified · sigma-rule
- Windows Defender Virus Scanning Feature Disabled · sigma-rule
- Windows Event Log Access Tampering Via Registry · sigma-rule
- Windows EventLog Autologger Session Registry Modification Via CommandLine · sigma-rule
- Windows Filtering Platform Blocked Connection From EDR Agent Binary · sigma-rule
- Windows Hypervisor Enforced Code Integrity Disabled · sigma-rule
- Windows Internet Hosted WebDav Share Mount Via Net.EXE · sigma-rule
- Windows LAPS Credential Dump From Entra ID · sigma-rule
- Windows Shell/Scripting Application File Write to Suspicious Folder · sigma-rule
- Windows Shell/Scripting Processes Spawning Suspicious Programs · sigma-rule
- Windows Vulnerable Driver Blocklist Disabled · sigma-rule
- Windows WebDAV User Agent · sigma-rule
- Windows Webshell Strings · sigma-rule
- WINEKEY Registry Modification · sigma-rule
- Winlogon Notify Key Logon Persistence · sigma-rule
- WinRAR Creating Files in Startup Locations · sigma-rule
- Winrs Local Command Execution · sigma-rule
- WMI Persistence - Command Line Event Consumer · sigma-rule
- WMI Persistence - Script Event Consumer File Write · sigma-rule
- WMImplant Hack Tool · sigma-rule
- Wmiprvse Wbemcomn DLL Hijack · sigma-rule
- WScript or CScript Dropper - File · sigma-rule
- WSL Kali-Linux Usage · sigma-rule
- Xwizard.EXE Execution From Non-Default Location · sigma-rule
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.