Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Named Pipe Creation: Alternate PowerShell Host via \PSHost
Alerts on creation of \PSHost named pipes to identify alternate PowerShell host usage via Windows pipe events.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowspipe_createdMedium72Free2019-09-12Windows: WinRM inbound network connections to ports 5985/5986 for PowerShell remoting
Alerts on WinRM inbound connections (ports 5985/5986) consistent with remote PowerShell remoting activity.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh383Free2019-09-12Windows Security: Detect WRITE_DAC on AD DS objects (Event ID 4662)
Flags AD DS Security Event 4662 activity indicating WRITE_DAC permission changes on domain objects.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityCritical101Free2019-09-12Windows Suspicious Debugger Registration via Image File Execution Options
Alerts on Windows attempts to set Image File Execution Options debuggers for logon screen binaries via command-line arguments.
Florian Roth (Nextron Systems), oscd.community, Jonhnathan Ribeiro, Huntrule TeamWindowsprocess_creationHigh92Free2019-09-06Windows Process Creation: Empire PowerShell UAC Bypass CommandLine Pattern
Flags Windows process creation events running Empire-style PowerShell UAC bypass command fragments.
Ecco, Huntrule TeamWindowsprocess_creationCritical61Free2019-08-30Windows Registry: Modification of WDigest IsCredGuardEnabled to Disable Credential Guard
Alerts on Windows registry changes to WDigest\IsCredGuardEnabled that may disable Credential Guard.
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research), Huntrule TeamWindowsregistry_eventHigh245Free2019-08-25PowerShell FromBase64String CommandLine Base64 Encoded Usage (Windows)
Flags PowerShell command lines containing FromBase64String along with base64-encoded UTF-16 marker patterns.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh72Free2019-08-24Windows: Alert on csc.exe Executing from User-Writable or Suspicious Paths
Alerts when csc.exe is launched from user/temp-like paths, indicating potential on-the-fly .NET compilation.
Florian Roth (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium123Free2019-08-24Windows PowerShell Base64 Command Line Executing IEX
Identifies Windows PowerShell processes with Base64-encoded command-line content that contains an IEX execution pattern.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh2310Free2019-08-23Windows: WmiPrvSE.exe Spawning a Child Process
Identifies child processes created by WmiPrvSE.exe on Windows, highlighting potential WMI-based execution attempts.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowsprocess_creationMedium92Free2019-08-15Windows Security: Non-System SeTakeOwnershipPrivilege granted on SCM database object
Flags non-system users requesting SeTakeOwnershipPrivilege on the SCM database object servicesactive in Windows Security 4674.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowssecurityMedium151Free2019-08-15Windows Security: SysKey-related LSA Registry Key Access (4656/4663)
Alerts on access to LSA registry keys used to compute SysKey based on Windows Security handle and registry object events.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh172Free2019-08-12Windows Security Event 4656: Non-system handle failure to SCM database object
Alerts on failed SCM database handle requests for ServicesActive from non-system logons using Windows Security Event ID 4656.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityMedium263Free2019-08-12Windows Security Event 4656: SAM Registry Hive Key Handle Requested
Flags Windows handle requests to registry keys ending with \SAM using Security EventID 4656.
Roberto Rodriguez @Cyb3rWard0g, Huntrule TeamWindowssecurityHigh122Free2019-08-12Windows Remote PowerShell Session via PS Module ContextInfo and wsmprovhost.exe
Flags Windows PowerShell remote session module context involving wsmprovhost.exe while filtering out archive module references.
Roberto Rodriguez @Cyb3rWard0g, Tim Shelton, Huntrule TeamWindowsps_moduleHigh103Free2019-08-10