Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Pass-the-Hash Activity via Security Event 4624 (LogonType 3 or 9)
Flags Windows 4624 successful logons consistent with Pass-the-Hash activity using NtLmSsp or seclogo.
Dave Kennedy, Jeff Warren (method) / David Vassallo (rule), Huntrule TeamWindowssecurityMedium30Free2019-06-14Windows Process Creation: Renamed jusched.exe Execution via Java Scheduler Names
Alerts when Java Update Scheduler descriptions are used to execute a process ending with \jusched.exe on Windows.
Markus Neis, Swisscom, Huntrule TeamWindowsprocess_creationHigh238Free2019-06-04Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Alerts when a new process is spawned under a Terminal Services (termsvcs) host context in Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh405Free2019-05-22WinRM Remote Access to LSASS via wsmprovhost.exe (Windows Process Access)
Flags remote WinRM (wsmprovhost.exe) process-access to lsass.exe, a high-risk credential-access behavior.
Patryk Prauze - ING Tech, Huntrule TeamWindowsprocess_accessHigh249Free2019-05-20Windows PowerShell Script Block Logging: Nishang Commandlet Names and Arguments
High-severity alert on PowerShell script blocks that reference known Nishang commandlets and exfil/execution helper names.
Alec Costello, Huntrule TeamWindowsps_scriptHigh248Free2019-05-16Windows: Outbound RDP (3389) Connections Initiated by Non-Standard Processes
Alerts on outbound port 3389 connections on Windows when initiated by an unapproved process, suggesting non-standard RDP tooling.
Markus Neis, Huntrule TeamWindowsnetwork_connectionHigh71Free2019-05-15Windows PowerShell Process Creation With Empire-Style EncodedCommand Launch Parameters
Flags PowerShell command lines containing hidden/stealth and encoded Empire-style launch parameters on Windows.
Florian Roth (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh127Free2019-04-20Windows Local User Creation (Security Event 4720)
Flags Windows Security Event ID 4720 indicating a local user account was created.
Patrick Bareiss, Huntrule TeamWindowssecurityLow3310Free2019-04-18Suspicious PowerShell/WScript Activity in WMI Event Consumer Commands
Identifies WMI event consumer commands containing PowerShell/WScript download-and-execute patterns like Net.WebClient and IEX.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Huntrule TeamWindowswmi_eventHigh113Free2019-04-15Windows: Suspicious Service Installation via Registry ImagePath Outside system32
Alerts on NalDrv/PROCEXP152 service ImagePath registry entries configured outside the expected system32 driver path.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowsregistry_setMedium42Free2019-04-08Windows Suspicious PROCEXP152.sys Creation in Local Temp Folder
Flags creation of PROCEXP152.sys in AppData\Local\Temp, excluding events from common Sysinternals executables.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowsfile_eventMedium209Free2019-04-08Windows Security Event 4673: SeLoadDriverPrivilege Use by Non-Whitelisted Processes
Flags Windows Event 4673 instances where SeLoadDriverPrivilege is exercised, suggesting attempts to load or unload kernel-mode drivers.
xknow (@xknow_infosec), xorxes (@xor_xes), Huntrule TeamWindowssecurityMedium108Free2019-04-08WmiPrvSE.exe Spawned PowerShell Child Process on Windows
Alerts on PowerShell spawning from WmiPrvSE.exe, a possible indicator of WMI-based remote execution.
Markus Neis @Karneades, Huntrule TeamWindowsprocess_creationMedium73Free2019-04-03Windows Security 5145 Network Share Access to Sensitive File Extensions
Alerts when Windows users access network-shared files with extensions commonly targeted for credential or data collection.
Samir Bousseaden, Huntrule TeamWindowssecurityMedium362Free2019-04-03Windows GPO Scheduled Task Persistence via SYSVOL ScheduledTasks.xml Writes (Security 5136/5145)
Alerts on GPO changes writing ScheduledTasks.xml to SYSVOL, indicating scheduled-task persistence at scale.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh156Free2019-04-03