Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry New File Association via exefile Handler (Classes\*.exefile)
Alerts on Windows registry changes creating a new file association that points to the exefile handler.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsregistry_setHigh103Free2021-11-19Windows WinRAR or RAR Utility Execution from Non-Default Installation Paths
Alerts on WinRAR/RAR process execution when launched from folders outside standard WinRAR installation paths.
Florian Roth (Nextron Systems), Tigzy, Huntrule TeamWindowsprocess_creationMedium102Free2021-11-17Windows ADCS Template Enrollment Supplies Subject and Risky EKU (Event ID 4898/4899)
Flags ADCS template load/update events (4898/4899) when risky EKU OIDs and enrollee-supplied subject are present.
Orlinum , BlueDefenZer, Huntrule TeamWindowssecurityHigh469Free2021-11-17Windows AD CS Certificate Template Updated/Created Enrollee Supplies Subject Flag
Alerts when AD CS certificate templates are created or updated with CT_FLAG_ENROLLEE_SUPPLIES_SUBJECT.
Orlinum , BlueDefenZer, Huntrule TeamWindowssecurityLow191Free2021-11-17Windows Suspicious Scheduled Task File Write Targeting System32 Tasks
Alerts on scheduled task storage writes under System32\Tasks originating from suspicious process locations.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh171Free2021-11-16Windows: reg.exe Adds BitLocker Policy Registry Values
Flags reg.exe registry additions targeting BitLocker policy keys associated with configuration changes.
frack113, Huntrule TeamWindowsprocess_creationHigh396Free2021-11-15Windows LSASS Memory Dump File Creation
Alerts on Windows file creation of LSASS memory dump artifacts identified by high-confidence filename patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsfile_eventHigh257Free2021-11-15Windows Office Apps Initiate Outbound Network Connections to Non-Private IPs
Alerts when Office app processes initiate outbound TCP/HTTP(S)/mail connections to non-private IPs, excluding common private and known provider ranges.
Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth (Nextron Systems), Tim Shelton, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium384Free2021-11-10Suspicious DNS Query Patterns for Cobalt Strike Beacons on Windows (Sysmon)
Alerts on Windows Sysmon DNS queries with QueryName patterns consistent with Cobalt Strike DNS beaconing.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdns_queryCritical173Free2021-11-09Windows HackTool Activity: Mimikatz Kerberos Ticket and MemSSP File Creation
Alerts on Windows file creation events for Mimikatz-related .kirbi and mimilsa.log files.
Florian Roth (Nextron Systems), David ANDRE, Huntrule TeamWindowsfile_eventCritical101Free2021-11-08Windows ZipExec-Style Suspicious PowerShell/Command Execution with Password-Protected ZIP
Flags Windows processes running ZipFolder zip commands with password and .zip filename parameters, optionally including deletion.
frack113, Huntrule TeamWindowsprocess_creationMedium162Free2021-11-07Windows Process Creation: cscript/wscript Register-App.vbs COM+ Registration
Alert on cscript/wscript running “.vbs -register” to register COM+ components, potentially leveraging register_app.vbs.
Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium269Free2021-11-05Windows: Cmdl32.EXE Arbitrary File Download Indicator via /vpn and /lan Flags
Flags cmdl32.exe executions using /vpn and /lan that may indicate arbitrary file retrieval behavior.
frack113, Huntrule TeamWindowsprocess_creationMedium93Free2021-11-03Windows Process Creation: PowerShell ExecutionPolicy Set to Bypass/Unrestricted
Alerts on PowerShell started with -ExecutionPolicy set to Bypass/Unrestricted, indicating a potentially insecure script execution posture.
frack113, Huntrule TeamWindowsprocess_creationMedium103Free2021-11-01Windows Process Creation: Command-Line Indicators of Crypto Mining
Alerts on Windows processes with command-line arguments matching common crypto miner pool and configuration indicators.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh151Free2021-10-26