%% Generated by tools/shroudcloud_archive.py from article frontmatter. Edits here are overwritten on the next run. %%
Open-source Sigma rules written against the threats profiled on this site, grouped by tactic.
## Execution
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-exec-anomalous-mshta]] | Anomalous MSHTA Usage | high | 2026-04-16 |
| [[edr-win-exec-browser-to-shell]] | Browser Spawning Script or Shell Execution | high | 2026-04-16 |
| [[edr-win-exec-clipboard-injection]] | FakeCaptcha Clipboard Injection via Explorer | high | 2026-04-16 |
| [[edr-win-exec-script-to-tmp-pipe]] | Script Host Piping Output to Temporary Files | medium | 2026-04-16 |
## Persistence
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-persist-rmm-deployment]] | Unauthorized RMM Tool Deployment | medium | 2026-04-14 |
| [[edr-win-persist-schtask-abuse]] | Suspicious Persistence via Scheduled Tasks or PowerShell | high | 2026-04-16 |
| [[edr-win-persist-winrm-schtask]] | Remote Scheduled Task Creation via WinRM | high | 2026-04-16 |
## Defense Evasion
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-def-defender-tampering]] | Windows Defender Tampering via PowerShell | medium | 2026-04-14 |
## Credential Access
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-cred-browser-esentutl]] | Browser Credential Theft via Esentutl | medium | 2026-04-14 |
| [[edr-win-cred-lsass-minidump]] | LSASS Memory Dump via Comsvcs.dll | high | 2026-04-14 |
| [[edr-win-cred-ntlm-internal-monologue]] | NTLM Hash Theft via Internal Monologue | high | 2026-04-14 |
| [[edr-win-cred-reg-hive-dump]] | Registry Hive Credential Dump | medium | 2026-04-14 |
| [[edr-win-cred-shadow-copy-abuse]] | Shadow Copy Access via LOLbin Parents | high | 2026-04-16 |
| [[edr-win-cred-veeam-db-access]] | Veeam Backup Credential Database Access | high | 2026-04-14 |
## Discovery
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-disc-adfind-enum]] | AdFind LDAP Enumeration | high | 2026-04-14 |
| [[edr-win-disc-clustered-enum]] | Clustered Endpoint Enumeration | medium | 2026-04-16 |
| [[edr-win-disc-net-priv-group-enum]] | Privileged Domain Group Enumeration via Net | high | 2026-04-14 |
| [[edr-win-disc-netscan-deployment]] | SoftPerfect Network Scanner Execution | medium | 2026-04-14 |
| [[edr-win-disc-nltest-domain-trusts]] | Domain Trust Enumeration via Nltest | high | 2026-04-14 |
## Lateral Movement
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-lat-anon-share-pull]] | Anonymous Share Staging (Null-Session Payload Pull) | high | 2026-04-20 |
| [[edr-win-lat-impacket-wmiexec]] | Impacket WmiExec Lateral Movement | critical | 2026-04-14 |
| [[edr-win-lat-rdp-enable]] | RDP Enablement via Registry or Firewall Modification | high | 2026-04-16 |
| [[edr-win-lat-remote-psexec]] | Remote PsExec Service Execution | low | 2026-04-14 |
| [[edr-win-lat-schtasks-remote]] | Native schtasks Remote Task Creation with UNC Target | high | 2026-04-20 |
| [[edr-win-lat-winrm-abuse]] | Remote Execution via WinRM Abuse | high | 2026-04-15 |
| [[edr-win-lat-wmic-remote-node]] | WMI Remote Process Execution via Native Binaries | high | 2026-04-16 |
## Command and Control
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-c2-reverse-tunneling]] | Reverse Tunnel Tool Execution | high | 2026-04-14 |
| [[edr-win-c2-susp-dns-tld]] | Suspicious DNS Request from High-Risk Process | high | 2026-04-16 |
## Exfiltration
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-exfil-rclone-usage]] | Rclone Data Exfiltration | high | 2026-04-14 |
| [[edr-win-exfil-winrar-staging]] | WinRAR Data Staging with Exfiltration Flags | - | 2026-04-15 |
| [[edr-win-exfil-winscp-transfer]] | WinSCP Command-Line File Transfer | - | 2026-04-15 |
## Impact
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[edr-win-impact-inhibit-recovery]] | System Recovery Inhibition | medium | 2026-04-14 |
## Correlation
| Rule | Detects | Level | Added |
|---|---|---|---|
| [[corr-ransomware-spread-multi-primitive]] | Per-Target Primitive Co-occurrence (Ransomware Spread-Module Signature) | critical | 2026-04-20 |
| [[edr-win-corr-proc-cluster-multi-host]] | Clustered Suspicious Process Creation Across Multiple Hosts | critical | 2026-04-16 |