Describe the behaviour you want to detect. SARA writes a starting Sigma rule with MITRE tags, false-positive guidance, and detection-engineering context. Anonymous, no account, best-effort generic detection.
VALIDT1218T1059.003T1204.002T1553
Sigma rule
title: Potential CVE-2023-36033 Exploitation via Protocol Handler Execution
id: d8ee069a-079d-4290-8910-b711d729a50e
status: experimental
description: |
Detects potential exploitation of CVE-2023-36033 (CISA KEV-listed).
Attackers bypass Mark-of-the-Web (MotW) protections by using URL protocol handlers
(search-ms:, search:, or ms-browser-extension:) via Office applications or command-line
execution to load malicious payloads from network shares without triggering SmartScreen warnings.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2023-36033
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36033
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
author: SARA Detection Engineering
date: 2026-08-15
tags:
- attack.t1218
- attack.t1059.003
- attack.t1204.002
- attack.t1553
logsource:
category: process_creation
product: windows
detection:
selection_protocol_cli:
CommandLine|contains:
- 'search-ms:'
- 'search:'
- 'ms-browser-extension:'
selection_protocol_office:
ParentImage|endswith:
- '\excel.exe'
- '\winword.exe'
- '\outlook.exe'
- '\powerpnt.exe'
CommandLine|contains:
- 'search-ms:'
- 'search:'
- 'ms-browser-extension:'
selection_explorer_share:
Image|endswith: '\explorer.exe'
CommandLine|contains:
- '\\\\'
- '.lnk'
- '.url'
filter_legit_search:
ParentImage|endswith: '\SearchHost.exe'
CommandLine|contains: 'search-ms:query='
condition: (1 of selection_protocol_*) or (selection_explorer_share and not filter_legit_search)
falsepositives:
- Legitimate internal use of custom search protocols via Windows Explorer.
- System administration scripts utilizing UNC paths for software deployment.
level: high
Sigma is the open, vendor-neutral format for log-based detections. One rule, written once, converts to Splunk SPL, Elastic ES|QL, KQL for Microsoft Sentinel, Sumo, Chronicle, QRadar, and more. Detection engineers love it for the same reason ATT&CK is the lingua franca for tactics — Sigma is the lingua franca for the queries that detect them.
GuideHow to use this tool
Describe the behaviour you want to detect in plain English. Be specific — "PowerShell encoded command spawned by an Office process" wins over "PowerShell abuse".
SARA writes a starting Sigma rule with the right logsource, fields, MITRE ATT&CK tags, and false-positive guidance.
Copy the YAML or convert to your target backend. Then tune the rule for your environment — the output is a starting point, not a tested artifact.
When to useWhen is the Sigma generator the right move?
Closing a coverage gap fast
You've got a fresh write-up of a TTP and need a starting detection in your stack today. Generate, tune, ship.
Onboarding a junior detection engineer
Pair-program with SARA: the generator produces the skeleton, the engineer learns by tuning, the team commits the result.
Translating between backends
You have a rule in one query language; describe it in English and get the Sigma version + conversions to every other backend.
Sanity-checking a hypothesis
Sketch a detection idea in 30 seconds before investing in a full DE sprint.
API
Want this in your SOAR or SIEM?
SARA Open ships an OpenAI-compatible API. Call POST /api/v1/sigma — Plain English in, valid Sigma YAML out, with MITRE tags and false-positive guidance.