Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry: Disable Windows Defender Exploit Guard Network Protection via Policy Override
Alerts on registry policy changes that override Exploit Guard Network Protection settings for Windows Defender.
Austin Songer @austinsonger, Huntrule TeamWindowsregistry_setMedium161Free2021-08-04Windows process access matching Cobalt Strike BOF injection call trace
Flags suspicious Windows process access consistent with CobaltStrike BOF injection using ntdll/KERNELBASE call traces and high GrantedAccess.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsprocess_accessHigh183Free2021-08-04PowerShell timestomping via file timestamp property and setter usage (Windows)
Identifies PowerShell timestomping attempts by matching script text that sets file creation, access, and write timestamps.
frack113, Huntrule TeamWindowsps_scriptMedium212Free2021-08-03PowerShell Virtualization Environment Discovery via WMI in ScriptBlockLogging (Windows)
Identifies PowerShell WMI queries for Win32 computer system and ACPI thermal data used to check virtualization environments.
frack113, Duc.Le-GTSC, Huntrule TeamWindowsps_scriptMedium354Free2021-08-03Windows Process Creation: ADCSPwn Command-Line Parameters Indicating ADCS Abuse
Identifies Windows processes with command-line arguments consistent with ADCSPwn targeting ADCS and a specified port.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh479Free2021-07-31Windows Process Creation: Recon Data Export via Command Prompt Redirection
Alerts when recon-related Windows utilities are launched with command-line output redirected to temp locations.
frack113, Huntrule TeamWindowsprocess_creationMedium133Free2021-07-30Windows: Suspicious Cabinet (CAB) File Expansion via expand.exe from Uncommon Paths
Flags expand.exe ("-F:") extracting cabinets when used from suspicious/uncommon Windows paths.
Bhabesh Raj, X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium527Free2021-07-30Windows PowerShell Recon via Export-Oriented Commands in Script Block Logging
Detects PowerShell script blocks performing recon queries (services/processes) and writing output to TEMP.
frack113, Huntrule TeamWindowsps_scriptMedium366Free2021-07-30PowerShell Keylogging via Get-Keystrokes and Win32 API Calls (GetAsyncKeyState, GetForegroundWindow)
Flags PowerShell script blocks containing Get-Keystrokes with GetAsyncKeyState/GetForegroundWindow for potential keylogging.
frack113, Huntrule TeamWindowsps_scriptMedium475Free2021-07-30Windows Named Pipe Creation: Cobalt Strike Malleable Profile PipeName Patterns
Alerts on Sysmon named pipe creation with PipeName patterns commonly used by Cobalt Strike malleable C2.
Florian Roth (Nextron Systems), Christian Burkard (Nextron Systems), Huntrule TeamWindowspipe_createdHigh161Free2021-07-30Windows Named Pipe Creation Matching Cobalt Strike Malleable C2 Profile Patterns
Alerts on Windows named pipe creation with PipeName patterns consistent with Cobalt Strike Malleable C2 behavior.
Florian Roth (Nextron Systems), Huntrule TeamWindowspipe_createdCritical224Free2021-07-30Windows WinDivert Driver Load via Image or Known IMPHASHes
Detects WinDivert-related Windows driver loads using loaded image paths or known IMPHASH values.
Florian Roth (Nextron Systems), Huntrule TeamWindowsdriver_loadHigh193Free2021-07-30PowerShell SAM Hive Copy via Volume Shadow Copy Paths on Windows
Flags PowerShell commands that copy the SAM hive from Volume Shadow Copy locations using .NET or PowerShell copy semantics.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh349Free2021-07-29Windows Process Creation: Automated Document and Directory Discovery via dir and findstr
Flags Windows commands combining recursive dir listing, FINDSTR usage, and document-type targeting in one execution.
frack113, Huntrule TeamWindowsprocess_creationMedium264Free2021-07-28PowerShell Script Block Collection of Documents via Recursive Get-ChildItem
Alerts on PowerShell file enumeration that recursively searches and includes common document extensions via Get-ChildItem.
frack113, Huntrule TeamWindowsps_scriptMedium363Free2021-07-28