Sigma rule coverage

281 events across 54 providers with Sigma detection rules, 4217 rule mappings total. Each rule links to its own page (predicates, exclusions, shared indicators). For the rule-centric ATT&CK browse across every vendor, see all detection rules; non-Windows Sigma rules are grouped by platform and technique at Sigma non-Windows coverage.

Microsoft-Windows-Security-Auditing

Event ID 675 Pre-authentication failed (legacy Windows 2003 Kerberos event; superseded by 4771). 1 rule
Event ID 4611 A trusted logon process has been registered with the Local Security Authority. 1 rule
Event ID 4616 The system time was changed. 2 rules
Event ID 4622 A security package has been loaded by the Local Security Authority. 1 rule
Event ID 4624 An account was successfully logged on. 29 rules
Event ID 4625 An account failed to log on. 11 rules
Event ID 4634 An account was logged off. 1 rule
Event ID 4647 User initiated logoff. 1 rule
Event ID 4648 A logon was attempted using explicit credentials. 3 rules
Event ID 4649 A replay attack was detected. 1 rule
Event ID 4656 A handle to an object was requested. 18 rules
Event ID 4657 A registry value was modified. 5 rules
Event ID 4658 The handle to an object was closed. 1 rule
Event ID 4661 A handle to an object was requested. 9 rules
Event ID 4662 An operation was performed on an object. 13 rules
Event ID 4663 An attempt was made to access an object. 22 rules
Event ID 4664 An attempt was made to create a hard link. 1 rule
Event ID 4673 A privileged service was called. 3 rules
Event ID 4674 An operation was attempted on a privileged object. 4 rules
Event ID 4688 A new process has been created. 735 rules
Event ID 4692 Backup of data protection master key was attempted. 1 rule
Event ID 4697 A service was installed in the system. 27 rules
Event ID 4698 A scheduled task was created. 7 rules
Event ID 4699 A scheduled task was deleted. 4 rules
Event ID 4701 A scheduled task was disabled. 2 rules
Event ID 4702 A scheduled task was updated. 2 rules
Event ID 4704 A user right was assigned. 2 rules
Event ID 4706 A new trust was created to a domain. 1 rule
Event ID 4717 System security access was granted to an account. 1 rule
Event ID 4719 System audit policy was changed. 3 rules
Event ID 4720 A user account was created. 8 rules
Event ID 4722 A user account was enabled. 1 rule
Event ID 4723 An attempt was made to change an account's password. 2 rules
Event ID 4724 An attempt was made to reset an account's password. 4 rules
Event ID 4726 A user account was deleted. 1 rule
Event ID 4727 A security-enabled global group was created. 1 rule
Event ID 4728 A member was added to a security-enabled global group. 12 rules
Event ID 4729 A member was removed from a security-enabled global group. 1 rule
Event ID 4730 A security-enabled global group was deleted. 1 rule
Event ID 4731 A security-enabled local group was created. 1 rule
Event ID 4732 A member was added to a security-enabled local group. 11 rules
Event ID 4737 A security-enabled global group was changed. 1 rule
Event ID 4738 A user account was changed. 9 rules
Event ID 4741 A computer account was created. 3 rules
Event ID 4742 A computer account was changed. 9 rules
Event ID 4743 A computer account was deleted. 1 rule
Event ID 4754 A security-enabled universal group was created. 1 rule
Event ID 4755 A security-enabled universal group was changed. 1 rule
Event ID 4756 A member was added to a security-enabled universal group. 11 rules
Event ID 4765 SID History was added to an account. 1 rule
Event ID 4766 An attempt to add SID History to an account failed. 1 rule
Event ID 4768 A Kerberos authentication ticket (TGT) was requested. 10 rules
Event ID 4769 A Kerberos service ticket was requested. 10 rules
Event ID 4770 A Kerberos service ticket was renewed. 1 rule
Event ID 4771 Kerberos pre-authentication failed. 4 rules
Event ID 4776 The domain controller attempted to validate the credentials for an account. 4 rules
Event ID 4781 The name of an account was changed. 5 rules
Event ID 4794 An attempt was made to set the Directory Services Restore Mode administrator password. 2 rules
Event ID 4799 A security-enabled local group membership was enumerated. 3 rules
Event ID 4800 The workstation was locked. 1 rule
Event ID 4825 A user was denied the access to Remote Desktop. 2 rules
Event ID 4898 Certificate Services loaded a template. 2 rules
Event ID 4899 A Certificate Services template was updated. 2 rules
Event ID 4904 An attempt was made to register a security event source. 1 rule
Event ID 4905 An attempt was made to unregister a security event source. 1 rule
Event ID 4950 A Windows Firewall setting has changed. 1 rule
Event ID 4964 Special groups have been assigned to a new logon. 1 rule
Event ID 5038 Code integrity determined that the image hash of a file is not valid. 1 rule
Event ID 5123 A configuration entry changed in the OCSP Responder Service. 1 rule
Event ID 5124 A security setting was updated on OCSP Responder Service. 1 rule
Event ID 5136 A directory service object was modified. 20 rules
Event ID 5137 A directory service object was created. 1 rule
Event ID 5140 A network share object was accessed. 5 rules
Event ID 5142 A network share object was added. 2 rules
Event ID 5143 A network share object was modified. 2 rules
Event ID 5145 A network share object was checked to see whether client can be granted desired access. 43 rules
Event ID 5156 The Windows Filtering Platform has permitted a connection. 3 rules
Event ID 5157 The Windows Filtering Platform has blocked a connection. 1 rule
Event ID 5379 Credential Manager credentials were read. 3 rules
Event ID 5382 Vault credentials were read. 1 rule
Event ID 5441 The following filter was present when the Windows Filtering Platform Base Filtering Engine started. 1 rule
Event ID 5447 A Windows Filtering Platform filter has been changed. 2 rules
Event ID 5449 A Windows Filtering Platform provider context has been changed. 1 rule
Event ID 6281 Code Integrity determined that the page hashes of an image file are not valid. 1 rule
Event ID 6416 A new external device was recognized by the system. 2 rules
Event ID 6423 The installation of this device is forbidden by system policy. 1 rule

Microsoft-Windows-Sysmon

Event ID 1 Process creation 1476 rules
Event ID 2 A process changed a file creation time 2 rules
Event ID 3 Network connection 61 rules
Event ID 4 Sysmon service state changed 1 rule
Event ID 6 Driver loaded 10 rules
Event ID 7 Image loaded 123 rules
Event ID 8 CreateRemoteThread 15 rules
Event ID 9 RawAccessRead 1 rule
Event ID 10 ProcessAccess 30 rules
Event ID 11 FileCreate 222 rules
Event ID 12 RegistryEvent (Object create and delete) 50 rules
Event ID 13 RegistryEvent (Value Set) 276 rules
Event ID 14 RegistryEvent (Key and Value Rename) 55 rules
Event ID 15 FileCreateStreamHash 9 rules
Event ID 16 ServiceConfigurationChange 2 rules
Event ID 17 PipeEvent (Pipe Created) 20 rules
Event ID 18 PipeEvent (Pipe Connected) 20 rules
Event ID 19 WmiEvent (WmiEventFilter activity detected) 4 rules
Event ID 20 WmiEvent (WmiEventConsumer activity detected) 4 rules
Event ID 21 WmiEvent (WmiEventConsumerToFilter activity detected) 4 rules
Event ID 22 DNSEvent (DNS query) 27 rules
Event ID 23 FileDelete (File Delete archived) 14 rules
Event ID 25 ProcessTampering (Process image change) 1 rule
Event ID 26 FileDeleteDetected (File Delete logged) 14 rules
Event ID 27 FileBlockExecutable 1 rule
Event ID 28 FileBlockShredding 1 rule
Event ID 29 FileExecutableDetected 2 rules
Event ID 255 Error report: UtcTime: UtcTime ID: ID Description: Description. 1 rule

Microsoft-Windows-Windows-Defender

Event ID 1006 1 rule
Event ID 1009 1 rule
Event ID 1013 1 rule
Event ID 1015 1 rule
Event ID 1116 4 rules
Event ID 1117 1 rule
Event ID 1119 1 rule
Event ID 1121 2 rules
Event ID 1151 1 rule
Event ID 3002 2 rules
Event ID 3007 1 rule
Event ID 5001 1 rule
Event ID 5007 5 rules
Event ID 5010 1 rule
Event ID 5012 1 rule
Event ID 5013 1 rule
Event ID 5101 1 rule

Microsoft-Windows-Windows-Firewall-With-Advanced-Security

Event ID 2002 1 rule
Event ID 2003 2 rules
Event ID 2004 6 rules
Event ID 2005 2 rules
Event ID 2006 1 rule
Event ID 2008 1 rule
Event ID 2009 1 rule
Event ID 2032 1 rule
Event ID 2033 1 rule
Event ID 2052 1 rule
Event ID 2059 1 rule
Event ID 2060 1 rule
Event ID 2071 3 rules
Event ID 2073 1 rule
Event ID 2082 1 rule
Event ID 2083 1 rule
Event ID 2097 3 rules

Microsoft-Windows-CodeIntegrity

Event ID 3001 Code Integrity determined an unsigned kernel module FileNameBuffer is loaded into the system. 1 rule
Event ID 3021 Code Integrity determined a revoked kernel module FileNameBuffer is loaded into the system. 1 rule
Event ID 3022 Code Integrity determined a revoked kernel module FileNameBuffer is loaded into the system. 1 rule
Event ID 3023 The driver FileNameBuffer is blocked from loading as the driver has been revoked by Microsoft. 1 rule
Event ID 3032 Code Integrity determined a revoked image FileNameBuffer is loaded into the system. 1 rule
Event ID 3033 Code Integrity determined that a process (ProcessNameBuffer) attempted to load FileNameBuffer that did not meet the RequestedPolicy signing level requirements. 1 rule
Event ID 3034 Code Integrity determined that a process (ProcessNameBuffer) attempted to load FileNameBuffer that did not meet the RequestedPolicy signing level requirements or violated code integrity p... 1 rule
Event ID 3035 Code Integrity determined a revoked image FileNameBuffer is loaded into the system. 1 rule
Event ID 3036 Windows is unable to verify the integrity of the file FileNameBuffer because the signing certificate has been revoked. 1 rule
Event ID 3037 Code Integrity determined an unsigned image FileNameBuffer is loaded into the system. 1 rule
Event ID 3077 Code Integrity determined that a process (Process Name) attempted to load File Name that did not meet the Requested Signing Level signing level requirements or violated code integrity p... 1 rule
Event ID 3082 Code Integrity determined kernel module FileNameBuffer that did not meet the WHQL requirements is loaded into the system. 1 rule
Event ID 3083 Code Integrity determined kernel module FileNameBuffer that did not meet the WHQL requirements is loaded into the system. 1 rule
Event ID 3104 Windows blocked file FileNameBuffer which has been disallowed for protected processes. 1 rule

MSSQLSERVER

Event ID 8128 1 rule
Event ID 15457 4 rules
Event ID 17199 1 rule
Event ID 17200 1 rule
Event ID 17201 1 rule
Event ID 17202 1 rule
Event ID 17810 1 rule
Event ID 18456 2 rules
Event ID 18470 1 rule
Event ID 33205 13 rules

Microsoft-Windows-AppXDeployment-Server

Event ID 400 Deployment DeploymentOperation operation with target volume MountPoint on Package PackageFullName from: Path finished successfully. 2 rules
Event ID 401 Deployment DeploymentOperation operation with target volume MountPoint on Package PackageFullName from: Path failed with error ErrorCode. 2 rules
Event ID 412 error ErrorCode: Deployment of package PackageFullName was blocked by AppLocker. 1 rule
Event ID 441 The package deployment operation is blocked by the "Allow deployment operations in special profiles" policy. 1 rule
Event ID 442 Deployment of package PackageFullName to volume MountPoint failed because deployments to non-system volumes are blocked by the "Disable deployment of Windows Store apps... 1 rule
Event ID 453 Package PackageFullName is blocked by a platform policy: PolicyReason. 1 rule
Event ID 454 Package PackageFullName is blocked by a platform policy: PolicyReason. 1 rule
Event ID 603 Started deployment DeploymentOperation operation on a package with main parameter Path and Options Flags and FlagsHigh. 1 rule
Event ID 854 Successfully added the following uri(s) to be processed: Path. 4 rules

Microsoft-Windows-SoftwareRestrictionPolicies

Event ID 865 Access to AttemptedPath has been restricted by your Administrator by the default software restriction policy level. 1 rule
Event ID 866 Access to AttemptedPath has been restricted by your Administrator by location with policy rule SrpRuleGuid placed on path RulePath. 1 rule
Event ID 867 Access to AttemptedPath has been restricted by your Administrator by software publisher policy. 1 rule
Event ID 868 Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid. 1 rule
Event ID 882 Access to AttemptedPath has been restricted by your Administrator by policy rule SrpRuleGuid. 1 rule

Microsoft-Windows-WindowsUpdateClient

Event ID 16 Unable to Connect: Windows is unable to connect to the automatic updates service and therefore cannot download and install updates according to the... 1 rule
Event ID 20 Installation Failure: Windows failed to install the following update with error errorCode: updateTitle. 1 rule
Event ID 24 Uninstallation Failure: Windows failed to uninstall the following update with error errorCode: updatelist. 1 rule
Event ID 213 Revert Failure: Windows failed to revert the following update with error errorCode: updatelist. 1 rule
Event ID 217 Commit Failure: Windows failed to commit the following update with error errorCode: updatelist. 1 rule

MsiInstaller

Event ID 1033 Windows Installer installed the product. 2 rules
Event ID 1034 Product: Data_0. 1 rule
Event ID 1040 Beginning a Windows Installer transaction: %0 2 rules
Event ID 1042 Ending a Windows Installer transaction: %0 2 rules
Event ID 11724 1 rule

ESENT

Event ID 216 1 rule
Event ID 325 3 rules
Event ID 326 2 rules
Event ID 327 2 rules

Microsoft-Windows-AppLocker

Event ID 8004 FilePathBuffer was prevented from running. 1 rule
Event ID 8007 FilePathBuffer was prevented from running. 1 rule
Event ID 8022 PackageBuffer was prevented from running. 1 rule
Event ID 8025 PackageBuffer was prevented from running. 1 rule

Microsoft-Windows-DHCP-Server

Event ID 1031 [EVENT_SERVER_CALLOUT_UNHANDLED_EXCEPTION] The installed server callout .dll file has caused an exception. 1 rule
Event ID 1032 [EVENT_SERVER_CALLOUT_LOAD_EXCEPTION] The installed server callout .dll file has caused an exception. The .dll file couldn't be loaded. 1 rule
Event ID 1033 [EVENT_SERVER_CALLOUT_LOAD_SUCCESS] The DHCP service has successfully loaded one or more callout DLLs. 1 rule
Event ID 1034 [EVENT_SERVER_READ_ONLY_GROUP_ERROR] The DHCP service has failed to load one or more callout DLLs. 1 rule

Microsoft-Windows-DNS-Server-Service

Event ID 150 The DNS server could not load or initialize the plug-in DLL Name. 2 rules
Event ID 770 A DNS server plugin DLL has been loaded from location param1 on server param2. 2 rules
Event ID 771 The V1 plugin interface has been implemented in server level plugin DLL. 1 rule
Event ID 6004 The DNS server received a zone transfer request from param1 for a non-existent or non-authoritative zone param2. 2 rules

Microsoft-Windows-Kerberos-Key-Distribution-Center

Event ID 35 The Key Distribution Center (KDC) encountered a ticket-granting-ticket (TGT) from another KDC (IssuingKDC) that did not contain a PAC attributes field 1 rule
Event ID 36 The Key Distribution Center (KDC) encountered a ticket that did not contain a PAC while processing a request for another ticket 1 rule
Event ID 37 The Key Distribution Center (KDC) encountered a ticket that did not contain information about the account that requested the ticket while processing a request for another ticket 1 rule
Event ID 38 The Key Distribution Center (KDC) encountered a ticket that contained inconsistent information about the account that requested the ticket 1 rule

Microsoft-Windows-TaskScheduler

Event ID 129 Task Scheduler launch task "Name" , instance "TaskName" with process ID Path. 3 rules
Event ID 140 User "TaskName" updated Task Scheduler task "Name". 1 rule
Event ID 141 User "TaskName" deleted Task Scheduler task "Name". 2 rules
Event ID 142 User "TaskName" disabled Task Scheduler task "Name". 1 rule

Service-Control-Manager

Event ID 7023 2 rules
Event ID 7034 1 rule
Event ID 7036 3 rules
Event ID 7045 55 rules

LsaSrv

Event ID 300 Groups assigned to a new logon. 1 rule
Event ID 6038 Microsoft Windows Server has detected that NTLM authentication is presently being used between clients and this server. 1 rule
Event ID 6039 Microsoft Windows Server has detected that NTLM authentication is being used between clients and this server. 1 rule

Microsoft-Windows-DriverFrameworks-UserMode

Event ID 2003 The UMDF Host Process (UMDFHostDeviceArrivalBegin.LifetimeId) has been asked to load drivers for device UMDFHostDeviceArrivalBegin.InstanceId. 1 rule
Event ID 2100 Received a Pnp or Power operation (UMDFHostDeviceRequest.RequestMajorCode, UMDFHostDeviceRequest.RequestMinorCode) for device UMDFHostDeviceRequest.InstanceId. 1 rule
Event ID 2102 Forwarded a finished Pnp or Power operation (UMDFHostDeviceRequest.RequestMajorCode, UMDFHostDeviceRequest.RequestMinorCode) to the lower driver for device UMDFHostDeviceRequest.InstanceId with sta... 1 rule

Microsoft-Windows-Eventlog

Event ID 104 The LogFileCleared.Channel log file was cleared. 3 rules
Event ID 517 The audit log was cleared (legacy Windows 2000/XP/2003 event; superseded by 1102). 1 rule
Event ID 1102 The audit log was cleared. 2 rules

Microsoft-Windows-TerminalServices-LocalSessionManager

Event ID 21 Remote Desktop Services: Session logon succeeded. 2 rules
Event ID 24 Remote Desktop Services: Session has been disconnected. 1 rule
Event ID 25 Remote Desktop Services: Session reconnection succeeded. 1 rule

PowerShell

Event ID 400 11 rules
Event ID 600 1 rule
Event ID 800 37 rules

Microsoft-Windows-Bits-Client

Event ID 3 The BITS service created a new job: jobTitle, with owner jobId. 2 rules
Event ID 16403 task_016403 5 rules

Microsoft-Windows-Directory-Services-SAM

Event ID 16990 The security account manager blocked a non-administrator from creating an Active Directory account in this domain with mismatched objectClass and u... 1 rule
Event ID 16991 The security account manager blocked a non-administrator from creating or renaming a computer account using an invalid sAMAccountName. 1 rule

Microsoft-Windows-NTLM

Event ID 8001 NTLM client blocked audit: Audit outgoing NTLM authentication traffic that would be blocked. 1 rule
Event ID 8002 NTLM server blocked audit: Audit Incoming NTLM Traffic that would be blocked. 1 rule

Microsoft-Windows-PowerShell

Event ID 4103 Payload Context: ContextInfo User Data: UserData. 71 rules
Event ID 4104 Creating Scriptblock text (MessageNumber of MessageTotal). 218 rules

Microsoft-Windows-PrintService

Event ID 316 Printer driver param1 for param2 param3 was added or updated. 1 rule
Event ID 808 The print spooler failed to load a plug-in module PluginDllName, error code ErrorCode. 1 rule

Microsoft-Windows-Security-Kerberos

Event ID 16 The Kerberos SSPI package failed to find the smart card certificate in the certificate store 1 rule
Event ID 27 Kerberos client event 27 (manifest stub). 1 rule

Microsoft-Windows-Security-Mitigations

Event ID 11 Process 'ProcessPath' (PID ProcessId) would have been blocked from loading the non-Microsoft-signed binary 'ImageName'. 2 rules
Event ID 12 Process 'ProcessPath' (PID ProcessId) was blocked from loading the non-Microsoft-signed binary 'ImageName'. 2 rules

Microsoft-Windows-WMI-Activity

Event ID 5859 Namespace = Operation_EssStarted.NamespaceName; NotificationQuery = Operation_EssStarted.Query; OwnerName = Operation_EssStarted.User; HostProcessID = Operation_EssStarted.Processid; Provider= Oper... 1 rule
Event ID 5861 Namespace = Operation_ESStoConsumerBinding.Namespace; Eventfilter = Operation_ESStoConsumerBinding.ESS (refer to its activate eventid:5859); Consumer = Operation_ESStoConsumerBinding.CONSUMER; Poss... 1 rule

ScreenConnect

Event ID 200 Executed command of length. 1 rule
Event ID 201 Transferred files with action 'Transfer'. 1 rule

TermDD

Event ID 50 1 rule
Event ID 56 1 rule

Application-Error

Event ID 1000 5 rules

Application-Popup

Event ID 26 1 rule

Microsoft-Windows-AppModel-Runtime

Event ID 201 Created process ProcessID for application ApplicationName in package PackageName. 1 rule

Microsoft-Windows-AppxPackagingOM

Event ID 157 The app package signature was validated for core content of the app package published by subjectName. 1 rule

Microsoft-Windows-Audit-CVE

Event ID 1 Possible detection of CVE: PossibleDetectionOfCVE. 1 rule

Microsoft-Windows-Backup

Event ID 524 The system catalog has been deleted. 1 rule

Microsoft-Windows-CAPI2

Event ID 70 For more details for this event, please refer to the "Details" section 1 rule

Microsoft-Windows-CertificateServicesClient-Lifecycle-System

Event ID 1007 A certificate has been exported. 1 rule

Microsoft-Windows-CertificationAuthority

Event ID 53 Active Directory Certificate Services denied request RequestId because 1 rule

Microsoft-Windows-DNS-Client

Event ID 3008 DNS query is completed for the name QueryName, type QueryType, query options QueryOptions with status QueryStatus Results QueryResults. 6 rules

Microsoft-Windows-Diagnosis-Scripted

Event ID 101 The scripted diagnostic engine started initializing a diagnostic package located at PackagePath. 1 rule

Microsoft-Windows-DistributedCOM

Event ID 10001 Unable to start a DCOM Server: param3 as param4/param5. 1 rule

Microsoft-Windows-IIS-Configuration

Event ID 29 Changes to 'Configuration' at 'ConfigPath' have successfully been committed 4 rules

Microsoft-Windows-Iphlpsvc

Event ID 4100 ISATAP router address IsatapRouter was set with status ErrorCode. 1 rule

Microsoft-Windows-Kernel-General

Event ID 16 The access history in hive HiveName was cleared updating KeysUpdated keys and creating DirtyPages modified pages. 1 rule

Microsoft-Windows-LDAP-Client

Event ID 30 LDAP search request 1 rule

Microsoft-Windows-Ntfs

Event ID 98 Volume DriveName (DeviceName) CorruptionActionState. 1 rule

Microsoft-Windows-SMBServer

Event ID 4000 The SMB client connection to the share was established 1 rule

Microsoft-Windows-Shell-Core

Event ID 28115 Shortcut for application Name with ID AppID and flags Flags is added to app resolver cache. 1 rule

Microsoft-Windows-TerminalServices-RemoteConnectionManager

Event ID 1149 Remote Desktop Services: User authentication succeeded. 1 rule

OpenSSH

Event ID 4 process: payload. 2 rules

Windows-Error-Reporting

Event ID 1001 2 rules