Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows: Detect esentutl.exe Copying Sensitive Credential Files via VSS
Alerts on esentutl.exe VSS usage and command lines referencing SAM/SECURITY/SYSTEM or ntds.dit copy targets.
Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationHigh122Free2019-10-22Windows Volume Shadow Copy Symlink Creation Using mklink
Flags Windows mklink commands that reference HarddiskVolumeShadowCopy to create symlinks.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsprocess_creationHigh123Free2019-10-22Windows: Unsigned DLL/EXE Image Loaded Into lsass.exe
Alerts on image loads into lsass.exe where the loaded image is unsigned.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowsimage_loadMedium151Free2019-10-22Windows Static Webshell Indicators via Suspicious File Extension Creation in Web Roots
Alerts on Windows creation of script-like files with webshell extensions in web root directories, excluding common benign temp and XAMPP paths.
Beyu Denis, oscd.community, Tim Shelton, Thurein Oo, Huntrule TeamWindowsfile_eventMedium152Free2019-10-22Windows Network Share File Transfers Targeting Credential and Memory Dump Paths
Alerts on network share access to credential-related files using Windows Security Event 5145.
Teymur Kheirkhabarov, oscd.community, Huntrule TeamWindowssecurityMedium164Free2019-10-22Windows Network Tool Use for Possible Packet Sniffing (tshark/windump)
Alerts on Windows executions of tshark or windump that indicate potential passive network traffic capture.
Timur Zinniatullin, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium93Free2019-10-21Windows Local Account Discovery via System Utilities Process Execution
Flags Windows processes that match utilities used to enumerate local user and account information.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow345Free2019-10-21Windows: Detect sc.exe Service Config binPath Changes to Suspicious Commands/Paths
Alerts when sc.exe updates a service binPath to point at suspicious commands or commonly abused directories.
Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh70Free2019-10-21Windows reg.exe Registry Query Reconnaissance (Process Creation)
Alerts on reg.exe process executions performing registry queries against high-value configuration and service keys.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium4510Free2019-10-21Windows Rar.exe Files Added to Archive Activity
Alerts when Windows rar.exe is used to add files to an archive using the " a " command-line pattern.
Timur Zinniatullin, E.M. Anhaus, oscd.community, Huntrule TeamWindowsprocess_creationLow169Free2019-10-21Windows: net.exe used to start a service with the start flag
Identifies Windows processes using net.exe/net1.exe with ' start ' to start services.
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community, Huntrule TeamWindowsprocess_creationLow50Free2019-10-21Windows Msxsl.exe Execution
Flags execution of the Windows MSXSL utility (msxsl.exe), which can be abused to process attacker-controlled XSL inputs.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationMedium70Free2019-10-21Windows Process: File Association Changes via assoc Command
Alerts on cmd.exe launches running the assoc command to modify Windows default file associations.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsprocess_creationLow50Free2019-10-21PowerShell ScriptBlock Winlogon Registry Modification via CurrentVersion\Winlogon
Detects PowerShell script blocks that modify Winlogon helper registry keys via Set-ItemProperty or New-Item on Windows.
Timur Zinniatullin, oscd.community, Huntrule TeamWindowsps_scriptMedium112Free2019-10-21Windows Process Creation: Suspicious CHCP Code Page Switch to Rare Locale
Alerts on suspicious chcp.com usage that switches Windows code pages to specific rare identifiers in process creation logs.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule TeamWindowsprocess_creationMedium444Free2019-10-14