Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Execution of PurpleSharp HackTool by Image Name or Executable Metadata
Alerts on process creation events consistent with running PurpleSharp.exe on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationCritical191Free2021-06-18Windows: Process writes registry to disable storage write-protection
Alerts on Windows process command lines that appear to disable storage write-protection via registry modification.
Sreeman, Huntrule TeamWindowsprocess_creationMedium181Free2021-06-11Windows Registry Set—Custom Outlook Today Page for Persistence
Flags registry writes that configure a custom Outlook Today URL using Outlook Today registry values.
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand, Huntrule TeamWindowsregistry_setHigh339Free2021-06-10Windows Persistence Attempt Using Outlook.exe to Create Outlook Forms Cache
Flags Outlook (outlook.exe) form file activity targeting local FORMS directories often used for persistence.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsfile_eventHigh201Free2021-06-10Windows Registry Changes for Outlook WebView Home Page URL Persistence
Alerts on Windows registry modifications affecting Outlook WebView home page URL settings.
Tobias Michalski (Nextron Systems), David Bertho (@dbertho) & Eirik Sveen (@0xSV1), Storebrand, Huntrule TeamWindowsregistry_setHigh474Free2021-06-09Windows Registry: Microsoft Office Protected View Disabled via Security Policy Keys
Flags Windows registry updates that disable Microsoft Office Protected View for attachments, internet files, UNC paths, or unsafe locations.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setHigh252Free2021-06-08Windows Process Creation: Exchange Transport Agent Installation via Install-TransportAgent
Flags Windows command-line executions containing Install-TransportAgent, indicating Exchange Transport Agent installation activity.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium251Free2021-06-08Windows MSExchange: Failed Transport Agent Installation (Install-TransportAgent)
Alerts on EventID 6 Exchange management events that include "Install-TransportAgent", indicating a failed Transport Agent installation attempt.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsmsexchange-managementHigh4210Free2021-06-08Windows MSExchange Transport Agent Installation via Install-TransportAgent
Flags Exchange Transport Agent installation attempts using the Install-TransportAgent command in MSExchange management telemetry.
Tobias Michalski (Nextron Systems), Huntrule TeamWindowsmsexchange-managementMedium503Free2021-06-08Windows AMSI Provider Registry Key Deletion (HKLM\Software\Microsoft\AMSI)
Alerts on deletion of AMSI provider registry key entries under HKLM\Software\Microsoft\AMSI, potentially indicating AMSI inspection impairment.
frack113, Huntrule TeamWindowsregistry_deleteHigh172Free2021-06-07PowerShell Tamper: Set-MpPreference disables Windows Defender scanning and protections
Flags PowerShell attempts to alter Windows Defender preferences using Set-MpPreference with Allow-style disable/default-action parameters.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsps_classic_provider_startHigh403Free2021-06-07Windows Sysmon Configuration Event Where Sysmon Stops
Alert on Sysmon status showing a stop event concurrent with a Sysmon configuration state change.
frack113, Huntrule TeamWindowssysmon_statusHigh447Free2021-06-04Windows Sysmon error events indicating service configuration update failures
Flags Windows Sysmon errors for failed service configuration/driver update attempts that may indicate tampering.
frack113, Huntrule TeamWindowssysmon_errorHigh172Free2021-06-04Windows Process Creation: SDelete Used for File Overwrite
Alerts when sdelete.exe runs in a way consistent with file overwrite to impede forensic recovery.
frack113, Huntrule TeamWindowsprocess_creationHigh296Free2021-06-03Windows WMI Shadow Copy Deletion via PowerShell
Identifies PowerShell commands that use WMI Win32_ShadowCopy to delete or remove Volume Shadow Copies.
frack113, Huntrule TeamWindowsps_classic_startHigh369Free2021-06-03