Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry Set: .NET COR/CORECLR Profiling Environment Variables Enabled
Alerts on registry writes enabling .NET CLR/CORECLR profiling variables like COR_ENABLE_PROFILING and COR_PROFILER.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Jimmy Bayne (@bohops), Huntrule TeamWindowsregistry_setMedium447Free2020-09-10Windows Process Creation: MpCmdRun.EXE Used to Download Files via DownloadFile url
Alerts when MpCmdRun.exe is executed with DownloadFile and url, indicating Defender utility file download behavior.
Matthew Matchen, Huntrule TeamWindowsprocess_creationHigh211Free2020-09-04WMI scrcons.exe Loading Script and WMI DLLs via Image Load (Windows)
Alerts when scrcons.exe loads vbscript/wbem/WMI script DLLs, suggesting WMI ActiveScriptEventConsumer activity.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsimage_loadMedium113Free2020-09-02Windows Process Creation: Mouse Lock Execution with “Misc314” Indicator
Alerts on Windows executions of Mouse Lock where Company includes “Misc314” and CommandLine contains “Mouse Lock_”.
Cian Heasley, Huntrule TeamWindowsprocess_creationMedium111Free2020-08-13Windows Defender windefend Event 1013: Malware detection history deletion
Alerts when Windows Defender deletes its malware/PUA detection history via windefend Event ID 1013.
Cian Heasley, Huntrule TeamWindowswindefendInformational328Free2020-08-13Windows Security Event 5145: SMB Write Access to Admin Share (C$)
Flags non-machine accounts writing via SMB to the C$ administrative share using Security EventID 5145.
Jose Rodriguez (@Cyb3rPandaH), OTR (Open Threat Research), Huntrule TeamWindowssecurityHigh182Free2020-08-06Windows windefend Event ID 5012: Windows Defender virus scanning disabled
Flags when Windows Defender disables virus scanning via windefend Event ID 5012.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh162Free2020-07-28Windows windefend: Windows Defender threat detection and mitigation events
Alerts on windefend events indicating Windows Defender malware detection and potential remediation activity.
Ján Trenčanský, Huntrule TeamWindowswindefendHigh203Free2020-07-28Windows windefend EventID 5001: Windows Defender real-time protection disabled
Flags windefend Event ID 5001 indicating Windows Defender real-time protection was disabled.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh202Free2020-07-28Windows windefend: Microsoft Defender malware and PUA scanning disabled (Event ID 5010)
Flags Windows Defender disabling malware and PUA scanning using Windefend Event ID 5010.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh213Free2020-07-28Windows Defender antimalware grace period expired (Event ID 5101)
Alerts when Windows Defender signals its antimalware grace period expired via windefend Event ID 5101.
Ján Trenčanský, frack113, Huntrule TeamWindowswindefendHigh121Free2020-07-28Windows Service Control Manager: Windows Defender Threat Protection Disabled
Flags Service Control Manager events where the Windows Defender Threat Protection (Defender Antivirus) service is stopped.
Ján Trenčanský, frack113, Huntrule TeamWindowssystemMedium478Free2020-07-28Windows webserver-spawned recon commands probing scripting tool help (perl/python/wget)
Flags webserver child processes running perl/python/python3/wget help commands to probe available tooling on the host.
Cian Heasley, Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh181Free2020-07-22Windows DLL Load Indicates Potential Azure Browser SSO OAuth Token Request Abuse
Alerts on MicrosoftAccountTokenProvider.dll loads on Windows, with process-based exclusions, as a signal for potential Azure Browser SSO token activity.
Den Iuzvyk, Huntrule TeamWindowsimage_loadLow171Free2020-07-15Windows Defender Exploit Guard blocks PSExec/WMI process creations (PsExec service and WMI provider)
Flags ASR blocks (windefend 1121) of process creations tied to WMI (wmiprvse.exe) or PSExec (psexesvc.exe).
Bhabesh Raj, Huntrule TeamWindowswindefendHigh153Free2020-07-14