Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Process Creation: Suspicious Command-Line Path Traversal Evasion Strings
Flags Windows command-line strings that look like “..\” path traversal evasion attempts, excluding known Google Drive and Citrix launcher patterns.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium346Free2021-10-26Windows Network Connections to Known Crypto Mining Pools
Flags Windows hosts making outbound connections to known cryptocurrency mining pool domains.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionHigh428Free2021-10-26Windows Browser Process Creating VHD/VHDX Files via Download
Alerts when a Windows browser process creates files containing .vhd, indicating potential VHD/VHDX staging.
frack113, Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Huntrule TeamWindowsfile_eventMedium132Free2021-10-25PowerShell Creating Startup .lnk Shortcut Persistence (Windows File Events)
Detects PowerShell writing .lnk files into the Windows Startup folder, a common persistence mechanism.
Christopher Peacock '@securepeacock', SCYTHE, Huntrule TeamWindowsfile_eventHigh1910Free2021-10-24Windows: CertOC.exe certificate utility loading a DLL via -LoadDLL
Flags CertOC.exe launching with -LoadDLL to load a specified DLL on Windows.
Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium70Free2021-10-23Windows Process Execution via WorkFolders.exe Launching control.exe
Alerts when WorkFolders.exe spawns a non-standard control.exe instance on Windows.
Maxime Thiebaut (@0xThiebaut), Huntrule TeamWindowsprocess_creationHigh143Free2021-10-21Windows process execution via stordiag.exe launching schtasks.exe, systeminfo.exe, or fltmc.exe
Detects stordiag.exe spawning schtasks.exe, systeminfo.exe, or fltmc.exe to support system discovery or config actions on Windows.
Austin Songer (@austinsonger), Huntrule TeamWindowsprocess_creationHigh142Free2021-10-21PowerShell Hidden WindowStyle Indicator in Script Block Text (Windows)
Flags PowerShell script block text indicating WindowStyle set to Hidden, suggesting concealed execution.
frack113, Tim Shelton (fp AWS), Huntrule TeamWindowsps_scriptMedium235Free2021-10-20PowerShell: Set-ExecutionPolicy to Unrestricted or Bypass
Alerts when PowerShell sets execution policy to Unrestricted or bypass, indicating weakened script execution controls.
frack113, Huntrule TeamWindowsps_scriptMedium193Free2021-10-20Windows Registry: Clearing RDP Client Connection History via MRU and Server Keys Deletion
Flags registry deletions that remove Windows RDP client connection history from Terminal Server Client MRU and Servers keys.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_deleteHigh457Free2021-10-19Windows PowerShell: Disable Windows Firewall Profile via Set-NetFirewallProfile
Flags PowerShell commands that disable one or more Windows Firewall profiles via Set-NetFirewallProfile -Enabled $false.
Austin Songer @austinsonger, Huntrule TeamWindowsps_scriptMedium132Free2021-10-12Windows vmtoolsd.exe Child Process Spawn via Scripting/Utility Binaries
Alert on vmtoolsd.exe spawning cmd/powershell/mshta/regsvr32/rundll32/wscript child processes with VM Tools batch-script command lines.
bohops, Bhabesh Raj, Huntrule TeamWindowsprocess_creationHigh153Free2021-10-08Windows Named Pipe Access to ADFS/WID Database by Uncommon Process
Alert on named pipe creation to the AD FS WID SQL query endpoint when initiated by uncommon processes.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowspipe_createdMedium152Free2021-10-08Windows: Suspicious Driver Installation via pnputil.exe
Flags pnputil.exe command lines indicating driver install/add actions targeting .inf files on Windows.
Hai Vaknin @LuxNoBulIshit, Avihay eldad @aloneliassaf, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium135Free2021-09-30Windows DataSvcUtil.exe Command-Line Exfiltration Using /in:, /out:, and /uri:
Alerts on DataSvcUtil.exe runs with /in:, /out:, and /uri: parameters that may indicate data exfiltration activity.
Ialle Teixeira @teixeira0xfffff, Austin Songer @austinsonger, Huntrule TeamWindowsprocess_creationMedium101Free2021-09-30