Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Recall Enabled via reg.exe Registry Changes (Windows)
Flags reg.exe commands that delete or set DisableAIDataAnalysis to 0 under WindowsAI to enable Windows Recall.
Sajid Nawaz Khan, Huntrule TeamWindowsprocess_creationMedium192Free2024-06-02Windows Executable Connects to portmap.io Domain Over Network
Alerts when a Windows process initiates a connection to a .portmap.io destination hostname.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium112Free2024-05-31Suspicious Web Browser Launch from PDF/Office Reader on Windows over HTTP(S)
Alerts when Acrobat/Office/PDF readers launch common browsers with HTTP(S) URLs, excluding known Microsoft and Foxit redirect patterns.
Joseph Kamau, Huntrule TeamWindowsprocess_creationMedium355Free2024-05-27Windows Process Access to Uncommon Target Images Using PROCESS_ALL_ACCESS
Alerts on Windows events granting PROCESS_ALL_ACCESS to processes with uncommon target image filenames.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_accessLow464Free2024-05-27Windows Network Connections to Cloudflared Tunnel Domains
Alerts when a Windows process initiates outbound connections to Cloudflared tunnel domain hostnames.
Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium416Free2024-05-27Windows: File Creation by mysqld.exe With Script/Executable Extensions
Alerts on file creation by mysqld.exe producing .bat/.exe/.ps1/.vbs and other executable or script file types on Windows.
Joseph Kamau, Huntrule TeamWindowsfile_eventHigh193Free2024-05-27Suspicious Child Process of KeyScrambler.exe on Windows
Alerts on KeyScrambler.exe launching cmd.exe, PowerShell, script hosts, regsvr32, or rundll32 as child processes.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium130Free2024-05-13PowerShell Start-NetEventSession Script Block Execution Indicating Potential Network Capture (Windows)
Alerts when PowerShell ScriptBlocks reference Start-NetEventSession, indicating potential network packet or event capture.
frack113, Huntrule TeamWindowsps_scriptMedium131Free2024-05-12Windows Registry: UAC PromptOnSecureDesktop Disabled
Detects setting UAC PromptOnSecureDesktop to 0 via Windows registry policy, disabling secure desktop for UAC prompts.
frack113, Huntrule TeamWindowsregistry_setMedium182Free2024-05-10Windows Registry: UAC notification disabled via UACDisableNotify set to DWORD 0x00000001
Alerts on registry changes that disable UAC notifications by setting UACDisableNotify to 0x00000001 on Windows.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium151Free2024-05-10Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh100Free2024-05-10Windows Process: File Recovery from Backup via wbadmin.exe
Flags wbadmin.exe executions that perform file recovery from backups based on recoveryTarget and itemtype:File arguments.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium90Free2024-05-10Windows Process Creation: wbadmin.exe Triggered for Backup of Sensitive Registry and NTDS Files
Alerts on wbadmin.exe backup commands that reference SAM/SECURITY/SYSTEM hives or NTDS.DIT.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh288Free2024-05-10Windows Firewall Allow Rule Added via WmiPrvSE.exe
Flags Windows firewall allow-rule additions where WmiPrvSE.exe is the modifying application.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asMedium442Free2024-05-10Windows: Alert on Outbound Connections Initiated by dialer.exe (Microsoft Phone Dialer)
Alerts on outbound connections started by Windows dialer.exe, excluding common local and reserved IP ranges.
CertainlyP, Huntrule TeamWindowsnetwork_connectionHigh80Free2024-04-26