Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Audit Policy Tampering Using auditpol.exe Command-Line Flags
Flags auditpol.exe executions that disable, clear, remove, or restore Windows audit policy settings.
Janantha Marasinghe (https://github.com/blueteam0ps), Huntrule TeamWindowsprocess_creationHigh319Free2021-02-02Windows Process Creation: Detect ShimCache Flush via rundll32 apphelp.dll/kernel32.dll
Flags rundll32 command-line activity that flushes ShimCache via apphelp.dll or kernel32.dll entry points.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh112Free2021-02-01Windows rundll32.exe execution with no parameters or arguments
Alerts on Windows rundll32.exe being started with an empty/no-parameter command line.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowsprocess_creationHigh151Free2021-01-31Windows WMIC Uninstall/Terminate Actions Targeting Security Products
Flags WMIC commands on Windows that attempt to uninstall or terminate security products or sensors using known vendor/product strings.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh153Free2021-01-30Windows Command-Line Disables Volume Shadow Copy (VSS) Snapshots
Flags Windows command lines that disable Volume Shadow Copy (VSS) snapshots via VSS Diag service switches.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh221Free2021-01-28Windows Process Creation: Raccine Removal via taskkill, registry and scheduled task deletion
Detects command-line activity that stops and removes Raccine components through process killing, registry deletion, and scheduled task removal.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh131Free2021-01-21Windows Service Installation (EID 4697) for SMB PsExec by Metasploit or Impacket
Alerts on Windows Event ID 4697 service installs matching SYSTEMROOT\8char.exe and on-demand start, consistent with PsExec-style SMB execution.
Bartlomiej Czyz, Relativity, Huntrule TeamWindowssecurityHigh163Free2021-01-21Windows Plink Remote Port Forwarding via -R Command Line
Alerts on Windows process command lines using Plink " -R " remote port forwarding to a local port.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh406Free2021-01-19Windows System Log: NTFS File System Driver Event 55 Indicates Possible NTFS Exploitation
Alerts on Windows NTFS Event ID 55 indicating a corrupted file record with a matching filename string in the event description.
Florian Roth (Nextron Systems), Huntrule TeamWindowssystemHigh322Free2021-01-11Windows Registry Persistence via VSTO Add-ins in Microsoft Office
Flags registry writes that register VSTO/Office add-ins for Outlook, Word, Excel, or PowerPoint persistence on Windows.
Bhabesh Raj, Huntrule TeamWindowsregistry_setMedium133Free2021-01-10Windows: Suspicious Child Processes Spawned by sqlservr.exe
Alerts when SQL Server (sqlservr.exe) spawns suspicious command/system tools on Windows.
FPT.EagleEye Team, wagga, Huntrule TeamWindowsprocess_creationHigh187Free2020-12-11Windows Registry Run Key Modification via winekey or team9 backdoor
Detects registry Run key changes to "Backup Mgr" that may indicate persistence via winekey/team9.
omkar72, Huntrule TeamWindowsregistry_eventHigh191Free2020-10-30Windows PsExec Execution Triggered by psexec.exe Process Creation
Flags process creation of PsExec (psexec.exe / psexec.c), a tool often used for remote execution and potential lateral movement.
omkar72, Huntrule TeamWindowsprocess_creationMedium205Free2020-10-30Windows Credential Access via Reg Add in LSA Registry Paths
Alerts when reg add commands target LSA registry settings and scecli entries commonly abused for credential access.
Sreeman, Huntrule TeamWindowsprocess_creationMedium93Free2020-10-29Windows Process Creation: bitsadmin.exe BITS jobs with SetNotifyCmdLine or remote file additions
Alerts on bitsadmin.exe command lines using /SetNotifyCmdLine or /Addfile to execute after download or stage remote files.
Sreeman, Huntrule TeamWindowsprocess_creationMedium162Free2020-10-29