Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Prefetch File Deletion via .pf File Removal
Flags deletion of .pf files in \\Windows\\Prefetch, a possible attempt to remove execution artifacts.
Cedric MAURUGEON, Huntrule TeamWindowsfile_deleteHigh214Free2021-09-29Windows Process Memory Dump Using RdrLeakDiag.exe (/memdmp|fullmemdmp)
Alerts on Windows executions of rdrleakdiag.exe that request full or targeted memory dumps via /memdmp or /fullmemdmp.
Cedric MAURUGEON, Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh4910Free2021-09-24PowerShell Live Memory Dump via Get-StorageDiagnosticInfo with -IncludeLiveDump (Windows)
Identifies PowerShell use of Get-StorageDiagnosticInfo with -IncludeLiveDump to trigger a live memory dump on Windows.
Max Altgelt (Nextron Systems), Huntrule TeamWindowsps_scriptHigh193Free2021-09-21Windows: Xwizard.exe Execution from Non-Default Directory
Alerts when Xwizard.exe starts from an unexpected Windows path, indicating potential misuse or side-loading.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh475Free2021-09-20PowerShell Add-DnsClientNrptRule Modifies NRPT Namespaces
Flags PowerShell scripts that add DNS Name Resolution Policy Table rules for a specified namespace.
Borna Talebi, Huntrule TeamWindowsps_scriptHigh192Free2021-09-14PowerShell ScriptBlock launching redirected comspec to Alternate Data Stream via '>'
Flags PowerShell script blocks using Start-Process with comspec and " > " redirection consistent with ADS-style file hiding.
frack113, Huntrule TeamWindowsps_scriptMedium93Free2021-09-02Windows Kerberos TGT Request with AD CS Certificate Thumbprint Anomalies (EventID 4768)
Identifies unusual certificate-associated Kerberos TGT (4768) requests targeting computer accounts on Windows.
Mauricio Velazco, Michael Haag, Huntrule TeamWindowssecurityHigh112Free2021-09-02Windows WMI Event Consumer with Encoded Payload Containing Suspicious Strings
Detects WMI event consumer encoded payloads containing suspicious execution-related strings on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowswmi_eventHigh364Free2021-09-01Windows Process Creation: Execution CommandLines Involving NTFS Alternate Data Streams
Alerts on Windows executions whose command lines reference NTFS Alternate Data Streams combined with specific file-data tools.
frack113, Huntrule TeamWindowsprocess_creationMedium2310Free2021-09-01Windows WMI Event Consumer (scrcons.exe) Creates Named Pipe
Flags scrcons.exe creating a Windows named pipe, using named pipe creation event telemetry.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdMedium187Free2021-09-01Windows Atera RMM Agent Installation via MsiInstaller Event ID 1033
Flags Windows MSI installs where installer logs indicate an AteraAgent installation (EventID 1033, MsiInstaller).
Bhabesh Raj, Huntrule TeamWindowsapplicationHigh142Free2021-09-01Windows UAC Bypass via ComputerDefaults.exe with Elevated Integrity Parent Process
Flags ComputerDefaults.exe runs at high/system integrity when the parent isn’t from typical system or Program Files paths.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh163Free2021-08-31Windows Registry UAC Bypass via winsat.exe LowerCaseLongPath and UACMe Path Parsing
Matches registry writes that reference winsat.exe using a LowerCaseLongPath construction consistent with UAC bypass path parsing.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setHigh199Free2021-08-30Windows Process Creation: UAC Bypass via winsat.exe Path Parsing
Alerts on elevated processes spawned by Temp-path winsat.exe with system32 winsat command-line content.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh454Free2021-08-30Windows UAC Bypass via NTFS Reparse Point: wusa.exe DLL Hijacking Process Behavior
Alerts on high-integrity wusa.exe launched from Temp update.msu with a dism.exe parent showing DismHost activity.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh133Free2021-08-30