
> Sigma Rule Search Engine β precise Sigma rule search for practitioners
| Votes | Title | Level | Status | Product | Author | Created |
|---|---|---|---|---|---|---|
|
Windows AppX Deployment Full Trust Package Installation
Detects the installation of MSIX/AppX packages with full trust privileges which run with elevated pr... |
medium | experimental | windows | Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-09-03 | |
|
Windows AppX Deployment Unsigned Package Installation
Detects attempts to install unsigned MSIX/AppX packages using the -AllowUnsigned parameter via AppXD... |
medium | experimental | windows | Michael Haag, Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-09-03 | |
|
New User Account Creation Attempt Via ADSI
Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces) using... |
medium | experimental | windows | William Gokah (idea), Raylee Hawkins, Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-08-19 | |
|
New User Account Creation Attempt Via ADSI in CommandLine
Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patt... |
medium | experimental | - | William Gokah (idea), Raylee Hawkins, Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-08-19 | |
|
PowerShell AppLocker Policy Discovery Via Get-AppLockerPolicy
Detects AppLocker policy enumeration attempts via PowerShell using the Get-AppLockerPolicy cmdlet an... |
low | experimental | windows | Tom3306 | 2026-08-19 | |
|
Suspicious Machine Account Replication - DcSync Indicator
Detects suspicious Active Directory Replication Service (ADRS) requests originating from a machine a... |
medium | test | windows | Benjamin Delpy, Florian Roth (Nextron Systems), Scott Dermett, Sorina Ionescu | 2026-08-05 | |
|
Potentially Suspicious Explicit Credential Local Logon
Detects potentially suspicious explicit credential logon events where the user is trying to logon wi... |
medium | experimental | windows | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-08-03 | |
|
Potentially Suspicious Image Load of Offreg.dll
Detects potentially suspicious loading of the Offline Registry Library (offreg.dll). Offreg.dll enab... |
medium | experimental | - | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-08-03 | |
|
Registry Hive File Staged Outside Standard User Profile Path
Detects the creation of a registry hive file (UsrClass.dat or NTUSER.DAT) outside of the standard us... |
high | experimental | - | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-08-03 | |
|
Suspicious Cross-User Process Spawn
Detects suspicious spawning of a process under a different user context than the parent process. Pro... |
medium | experimental | - | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-08-03 | |
|
AWS Bedrock Guardrail Updated
Detects updates to an Amazon Bedrock guardrail, which may indicate attempts to weaken model safety c... |
medium | experimental | aws | Marco Pedrinazzi (@pedrinazziM) (InTheCyber) | 2026-07-27 | |
|
AWS Bedrock Guardrail Deleted
Detects deletion of an Amazon Bedrock guardrail, which may indicate attempts to remove model safety ... |
medium | experimental | aws | Marco Pedrinazzi (@pedrinazziM) (InTheCyber) | 2026-07-27 | |
|
AppLocker Application Would Have Been Blocked
Detects when AppLocker "Audit only" enforcement mode reports that an Application, DLL, Script, MSI, ... |
medium | experimental | windows | heyyanu | 2026-07-09 | |
|
Failed Event Log Clear Via WMI NTEventLogFile ClearEventLog
Detects failed attempts to clear Windows event logs via the WMI NTEventLogFile ClearEventLog method.... |
medium | test | windows | Swachchhanda Shrawan Poudel (Nextron Systems) | 2026-07-09 | |
|
User Added to an Administrator's Azure AD Role
User Added to an Administrator's Azure AD Role... |
medium | test | azure | RaphaΓ«l CALVET, @MetallicHack | 2026-07-03 | |
|
Azure Application Deleted
Identifies when a application is deleted in Azure.... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Disabled MFA to Bypass Authentication Mechanisms
Detection for when multi factor authentication has been disabled, which might indicate a malicious a... |
medium | test | azure | '@ionsor' | 2026-07-03 | |
|
Azure Device No Longer Managed or Compliant
Identifies when a device in azure is no longer managed or compliant... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Azure Service Principal Created
Identifies when a service principal is created in Azure.... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Azure Service Principal Removed
Identifies when a service principal was removed in Azure.... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Azure Owner Removed From Application or Service Principal
Identifies when a owner is was removed from a application or service principal in Azure.... |
medium | test | azure | Austin Songer @austinsonger | 2026-07-03 | |
|
Antivirus - Remote Access Tools Signature
Detects a highly relevant Antivirus alert that reports a remote access tool. This event must not be ... |
critical | experimental | - | Arnim Rupp (Nextron Systems) | 2026-07-01 | |
|
Antivirus - APT Malware Signature
Detects a highly relevant Antivirus alert that reports APT malware. This event must not be ignored j... |
critical | experimental | - | Arnim Rupp (Nextron Systems) | 2026-07-01 | |
|
Antivirus - Exploitation Framework Signature
Detects a highly relevant Antivirus alert that reports an exploitation framework. This event must no... |
critical | stable | - | Florian Roth (Nextron Systems), Arnim Rupp | 2026-07-01 | |
|
New Agent Skills Installation Attempt Via Node.EXE
Detects the attempt to install new skills for AI agents using the "npx skills" command. Agent skills... |
medium | experimental | windows | Marco Pedrinazzi (@pedrinazziM) (InTheCyber) | 2026-07-01 |