Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows spoolsv.exe Child Process Execution Indicators
Flags suspicious process executions where spoolsv.exe (print spooler) spawns utility, scripting, or rundll32 children with high integrity.
Justin C. (@endisphotic), @dreadphones (detection), Thomas Patzke (Sigma rule), Huntrule TeamWindowsprocess_creationHigh221Free2021-07-11Windows DNS Queries for IP Lookup Service Domains from Non-Browser Processes
Flags suspicious DNS lookups to IP-check API domains on Windows when they come from non-browser executables.
Brandon George (blog post), Thomas Patzke, Huntrule TeamWindowsdns_queryMedium223Free2021-07-08Windows Process Creation: MpCmdRun.exe Removing All Windows Defender Definitions
Flags MpCmdRun.exe launched to remove all Windows Defender definition files.
frack113, Huntrule TeamWindowsprocess_creationHigh191Free2021-07-07Windows Registry Defender Exclusions Path Set (Microsoft\Windows Defender\Exclusions)
Identifies registry updates that reference the Windows Defender Exclusions path, indicating potential defense impairment.
Christian Burkard (Nextron Systems), Huntrule TeamWindowsregistry_setMedium497Free2021-07-06Windows Defender Exclusions Added via Windefend (Event ID 5007)
Alerts on Windows Defender exclusion additions based on windefend Event ID 5007 configuration change events.
Christian Burkard (Nextron Systems), Huntrule TeamWindowswindefendMedium243Free2021-07-06Windows windefend: Detect Tamper Protection blocks changes to Microsoft Defender settings
Flags Defender tamper protection blocks to disable key Microsoft Defender Antivirus and real-time protection settings.
Bhabesh Raj, Nasreddine Bencherchali, Huntrule TeamWindowswindefendHigh231Free2021-07-05Windows SMB Client Security: Rejected Guest Logon with Blank UserName
Flags rejected SMB guest/anonymous-style logons on Windows when the SMB username is blank.
Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Huntrule TeamWindowssmbclient-securityMedium258Free2021-06-30Windows Registry Service Install Indicators for Cobalt Strike Staging
Identifies suspicious Windows service installation registry writes tied to ADMIN$/.exe and %COMSPEC% start powershell patterns.
Wojciech Lesicki, Huntrule TeamWindowsregistry_setHigh233Free2021-06-29Windows reg.exe Run Key Modification for Persistence via Process Creation
Alerts on reg.exe commands that add values to Windows Run registry keys, a common persistence technique.
Florian Roth (Nextron Systems), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium150Free2021-06-28Windows Process Creation: WMIC.exe ActiveScriptEventConsumer Creation Attempt
Alerts on WMIC.exe command lines attempting to create an ActiveScriptEventConsumer for event-driven script execution.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh504Free2021-06-25Windows PortProxy Registry Key Modified for Port Forwarding
Alerts when PortProxy port-forwarding registry entries under the Windows TCP v4tov4 path are added or modified.
Andreas Hunkeler (@Karneades), Huntrule TeamWindowsregistry_eventMedium453Free2021-06-22Windows: Detect execution of renamed megasync.exe (original MegaSync) via process creation
Flags process launches where megasync.exe appears under a renamed or nonstandard execution context based on process creation fields.
Sittikorn S, Huntrule TeamWindowsprocess_creationHigh4610Free2021-06-22Windows LDAP Client Event ID 30 Active Directory enumeration via LDAP search filters
Flags LDAP search queries indicative of Active Directory reconnaissance/enumeration using Event ID 30 filter patterns.
Adeem Mawani, Huntrule TeamWindowsldapMedium459Free2021-06-22Windows: Suspicious Child Process Spawned by scrcons.exe (Script Event Consumer)
Alerts on rare child processes spawned by scrcons.exe, which may indicate abuse of Script Event Consumer for execution.
Sittikorn S, Huntrule TeamWindowsprocess_creationHigh393Free2021-06-21Windows Registry: New TaskCache entry created by unusual process image
Alerts when TaskCache registry entries are created by processes other than a defined set of expected Windows binaries.
Syed Hasan (@syedhasan009), Huntrule TeamWindowsregistry_setHigh212Free2021-06-18