Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Registry CurrentControlSet Control Autorun/ASEP Key Modification
Alerts on Registry changes to Windows ASEP-related keys under CurrentControlSet\Control that can enable persistence.
Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule TeamWindowsregistry_setMedium256Free2019-10-25Windows Registry Autorun/ASEP Key Modification for Persistence
Alerts on registry modifications to common Windows autorun and persistence extensibility keys indicative of auto-start behavior.
Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), wagga (name), Huntrule TeamWindowsregistry_setMedium266Free2019-10-25Windows Registry Classes Autorun Key Modification for Persistence
Alerts on registry changes under Windows Classes shell extension/ASEP paths that may enable persistence.
Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split), Huntrule TeamWindowsregistry_setMedium82Free2019-10-25Windows Registry: AppCertDlls NewName/TargetObject Creation for DLL Load Persistence
Alerts on Windows registry changes involving AppCertDlls paths that can enable malicious DLL loading for persistence.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowsregistry_eventMedium73Free2019-10-25Windows Registry: Add-on DelegateExecute persistence via Narrator Feedback-Hub AppX key
Flags registry value deletions on a Narrator Feedback-Hub AppX DelegateExecute path used for persistence.
Dmitriy Lifanov, oscd.community, Huntrule TeamWindowsregistry_eventHigh41Free2019-10-25Windows: Registry CreateKey/Rename of HKLM\SYSTEM\CurrentControlSet\Control\MiniNt
Flags registry creation or renaming of the MiniNt key that can impair Windows event logging after reboot.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowsregistry_eventHigh83Free2019-10-25Windows reg.exe Direct Modification of Registry Autostart Extensibility Keys (ASEP)
Flags reg.exe adding registry autostart (ASEP) entries under common Run/Winlogon/Policy paths.
Victor Sergeev, Daniil Yugoslavskiy, oscd.community, Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium379Free2019-10-25Windows netsh.exe "add helper" execution for custom helper DLL loading
Flags netsh.exe being run with "add helper" parameters that can register a custom helper DLL.
Victor Sergeev, oscd.community, Huntrule TeamWindowsprocess_creationMedium267Free2019-10-25Windows Regsvr32.exe Initiated Network Connection
Flags outbound network connections initiated by Regsvr32.exe based on process image and connection initiation telemetry.
Dmitriy Lifanov, oscd.community, Huntrule TeamWindowsnetwork_connectionMedium122Free2019-10-25Windows DNS Queries Initiated by Regsvr32.exe
Flags DNS queries made by regsvr32.exe based on the querying process image path.
Dmitriy Lifanov, oscd.community, Huntrule TeamWindowsdns_queryMedium101Free2019-10-25Windows Security Event DCShadow Indicators via New Service Principal Name GC/
Flags Windows Security events where a servicePrincipalName starting with "GC/" is created, consistent with DCShadow-style SPN registration.
Ilyas Ochkov, oscd.community, Chakib Gzenayi (@Chak092), Hosni Mribah, Huntrule TeamWindowssecurityMedium72Free2019-10-25Windows Security: New or Renamed User Account Name Containing '$'
Alerts on Windows user create/rename events when the account name contains '$', excluding the HomeGroupUser$ exception.
Ilyas Ochkov, oscd.community, Huntrule TeamWindowssecurityMedium113Free2019-10-25Windows Process Creation: WSReset.exe Used with Non-CONHOST Child Process
Alerts when wsreset.exe spawns a process other than conhost.exe, a potential UAC-bypass precursor.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Florian Roth, Huntrule TeamWindowsprocess_creationHigh315Free2019-10-24Windows: Detect Fodhelper.exe spawned processes indicative of UAC bypass
Flags process creation where the parent is Fodhelper.exe, a common UAC bypass execution pattern on Windows.
E.M. Anhaus (originally from Atomic Blue Detections, Tony Lambert), oscd.community, Huntrule TeamWindowsprocess_creationHigh70Free2019-10-24Windows: Command-line execution of cmstp.exe with INF install/silent/autobind flags (UAC bypass pattern)
Alerts when cmstp.exe is launched with INF installation and silent/auto options indicating a UAC-bypass style behavior.
E.M. Anhaus (originally from Atomic Blue Detections, Endgame), oscd.community, Huntrule TeamWindowsprocess_creationHigh192Free2019-10-24