Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
PowerShell Write-Hijack HackTool Creates .bat for DLL Hijack Execution (Windows)
Flags PowerShell creating .bat files consistent with PowerUp Write-Hijack DLL abuse on Windows.
Subhash Popuri (@pbssubhash), Huntrule TeamWindowsfile_eventHigh131Free2021-08-21Windows: Detect reg.exe Changing Screen Saver Registry Settings for .scr Payloads
Flags reg.exe command lines that modify HKCU desktop screensaver settings and configure a .scr screen saver payload.
frack113, Huntrule TeamWindowsprocess_creationMedium171Free2021-08-19PowerShell WMI Event Subscription Persistence via New-CimInstance
Finds PowerShell creating WMI __EventFilter and CommandLineEventConsumer objects for event-triggered persistence.
frack113, Huntrule TeamWindowsps_scriptMedium393Free2021-08-19Windows PowerShell: Add-Content to $profile for Potential Persistence
Detects PowerShell Add-Content writing to $profile, especially when paired with common command-loading or execution payloads.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_scriptMedium203Free2021-08-18Windows Procdump Process Execution
Alerts on execution of Sysinternals Procdump (32/64 variants) based on process creation image path.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium522Free2021-08-16Windows whoami.exe Execution from Suspicious Parent Processes
Alerts on whoami.exe runs where the parent process is not a typical shell or monitoring agent.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium112Free2021-08-12Windows whoami.exe Renamed Execution via Mismatched OriginalFileName
Alerts when a renamed process still reports OriginalFileName as whoami.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical90Free2021-08-12Windows Maldoc Process Injection via winword.exe CallTrace from LittleCorporal
Flags winword.exe process injection where the call trace matches LittleCorporal-generated Maldoc activity on Windows.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh172Free2021-08-09PowerShell ShellIntel Commandlet Abuse via ScriptBlock Logging
Flags PowerShell script blocks that reference known ShellIntel commandlets tied to exploitation activity.
Max Altgelt (Nextron Systems), Tobias Michalski (Nextron Systems), Huntrule TeamWindowsps_scriptHigh161Free2021-08-09Microsoft Exchange: Mailbox export to UNC path or .aspx filename with possible role assignment
Flags Exchange mailbox export commands targeting UNC paths with .aspx or granting the Mailbox Import Export role.
Florian Roth (Nextron Systems), Rich Warren, Christian Burkard (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical284Free2021-08-09Windows Exchange Management: Set-OabVirtualDirectory after ProxyLogon exploitation
Flags Exchange management command lines invoking Set-OabVirtualDirectory with suspicious external URL/script injection patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsmsexchange-managementCritical4010Free2021-08-09Windows AnyDesk Silent Installation via Command-Line Flags
Identifies AnyDesk being silently installed on Windows using --install, --start-with-win, and --silent command-line flags.
Ján Trenčanský, Huntrule TeamWindowsprocess_creationHigh243Free2021-08-06Windows esentutl Usage with /p Flag for Credential Access
Flags Windows executions of esentutl when used with the /p parameter to access credentials-related files.
sam0x90, Huntrule TeamWindowsprocess_creationMedium152Free2021-08-06Windows Registry: Tamper Protection Disabled in Microsoft Defender Features
Flags registry changes that set Microsoft Defender Tamper Protection to disabled (DWORD 0x0), excluding expected MsMpEng update activity.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setMedium3710Free2021-08-04Windows Registry: Disabling Windows Defender PUA Protection via PUAProtection DWORD
Flags registry changes that set Windows Defender PUAProtection DWORD to 0x00000000 to disable PUA protection.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setHigh256Free2021-08-04