Search and filter across all detection sources
922 rules
0x103800
Detects process access requests to the LSASS process with specific call trace calls and access masks. This behaviour is expressed by many credential dumping tools such as Mimikatz, NanoDump, Invoke-Mimikatz, Procdump and even the Taskmgr dumping feature.
0x1FFFFF
Detects process LSASS memory dump using Mimikatz, NanoDump, Invoke-Mimikatz, Procdump or Taskmgr based on the CallTrace pointing to ntdll.dll, dbghelp.dll or dbgcore.dll for win10, server2016 and up
abusing_attribexe_to_change_file_attributes
Detects possible abuse of attrib.exe to hide files and folder or to mark a file as a system file License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
abusing_azure_browser_sso
Detects abusing Azure Browser SSO by requesting OAuth 2.0 refresh tokens for an Azure-AD-authenticated Windows user (i.e. the machine is joined to Azure AD and a user logs in with their Azure AD account) wanting to perform SSO authentication in the browser. An attacker can use this to authenticate to Azure AD in a browser as that user. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
abusing_managebdewsf
Detects abusing of deprecated manage-bde.wsf. Tampering with manage-bde.wsf to run things in unattended ways. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
abusing_security_support_provider_and_authentication_packages
Detects activity that abuses Windows Security Support Provider (SSP) and Authentication Packages (AP) that come in the form of DLLs that get injected into LSASS.exe process on system boot or dynamically via AddSecurityPackage API. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
abusing_settingcontentms_to_launch_arbitrary_shell_command_execution
None License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
abusing_windows_telemetry_compattelrunnerexeaudit_rule
Detects abusing of CompatTelRunner.exe for persistance. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
account_discovery_activity_detector_sysmon_behavior
This detects characteristics of account discovrery activity that adversaries could use License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
account_tampering__suspicious_failed_logon_reasons
This method uses uncommon error codes on failed logons to determine suspicious activity and tampering with accounts that have been disabled or somehow restricted. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
acer_quick_access__dll_searchorder_hijacking_and_potential_abuses
Detects (CVE-2019-18670) exploitation attempt License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
active_directory_as_a_c2_command__control
Active Directory is a Central Authentication and Access control. It isimportant to control it. The service name does not appear either. The importantthing is to check the displayname License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
active_directory_replication_from_non_machine_account
Detects potential abuse of Active Directory Replication Service (ADRS) from a non machine account to request credentials. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
activity_related_to_ntdsdit_domain_hash_retrieval
Detects suspicious commands that could be related to activity that uses volume shadow copy to steal and retrieve hashes from the NTDS.dit file remotely License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
addition_of_sid_history_to_active_directory_object
An attacker can use the SID history attribute to gain additional privileges. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
add_programs_to_firewall_exclusion_from_temp_directory_sysmon
Add Programs To Firewall Exclusion From Temp Directory. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
ADFS DKM Key Access
Detects access to the AD contact object to read the AD FS DKM (distributed key manager) master key value
Admin$
Detects access to $ADMIN share. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
admin_user_rdp
It shows those who log in remotely with admin account. License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
admin_user_remote_logon
Detect remote login by Administrator user depending on internal pattern License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
ad_privileged_users_or_groups_reconnaissance
Detect priv users or groups recon based on 4661 eventid and known privileged users or groups SIDs License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
adwind_detection
Detects AdWind activity (also known as AlienSpy, Frutas, Unrecom, Sockrat, JSocket and jRat) License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
adwind_rat__jrat
Detects javaw.exe in AppData folder as used by Adwind / JRAT License: https://github.com/Neo23x0/sigma/blob/master/LICENSE.Detection.Rules.md.
adwind_rat__jrat_part_1
adwind_rat__jrat_part_2