Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
2,298 rules
Windows Security 4661 Detects Privileged AD User/Group SID Enumeration via SAM
Identifies SAM_USER/SAM_GROUP access events (4661) aimed at privileged SIDs or names containing 'admin' while ignoring computer accounts.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh367Free2019-04-03Windows Security 5136: Modify AD ACL for DCSync Extended Right via ntSecurityDescriptor
Flags directory ACL changes (EventID 5136) that include DCSync extended right GUIDs in ntSecurityDescriptor for DNS objects.
Samir Bousseaden, Roberto Rodriguez @Cyb3rWard0g, oscd.community, Tim Shelton, Maxence Fossat, Huntrule TeamWindowssecurityHigh304Free2019-04-03Windows Suspicious EXE in User Directory Launched by Microsoft Office Applications
Alert on Office spawning a .exe from C:\users\ (except when the child is Teams.exe).
Jason Lynch, Huntrule TeamWindowsprocess_creationHigh71Free2019-04-02Windows Security Logon Event ID 4800: Workstation Lock After Inactivity
Locked Workstation
Alexandr Yampolskyi, SOC Prime, Huntrule TeamWindowssecurityInformational347Free2019-03-26Windows ADSI Schema Cache (.sch) File Creation by Uncommon Process
Alerts on .sch cache file creation in the Windows SchCache directory by uncommon executables.
xknow @xknow_infosec, Tim Shelton, Huntrule TeamWindowsfile_eventMedium199Free2019-03-24Windows Security Event 5136: Suspicious LDAP attribute display names used
Alerts on Event 5136 containing specific LDAP display names indicative of LDAP-based data exchange.
xknow @xknow_infosec, Huntrule TeamWindowssecurityHigh125Free2019-03-24Windows ETW Trace Evasion via Clearing/Disabling Logs or Providers
Identifies command-line attempts to clear/disable ETW traces or remove/modify ETW providers on Windows.
"@neu5ron, Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Huntrule Team"Windowsprocess_creationHigh152Free2019-03-22Windows: certutil.exe File Encoding to Base64 Using the -encode Flag
Alerts on Windows certutil.exe executions using -encode to base64-encode a file.
Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsprocess_creationMedium100Free2019-02-24Windows Process Creation: Alert on Suspicious Parent of Core System Executables
Flags when core Windows executables (e.g., svchost, lsass, winlogon) are spawned by suspicious parent processes.
vburov, Huntrule TeamWindowsprocess_creationLow162Free2019-02-23Windows mshta.exe Execution Using Non-HTA File Extensions
Alerts on mshta.exe launched with command-line indicators for suspicious non-HTA file types and VBScript.
Diego Perez (@darkquassar), Markus Neis, Swisscom (Improve Rule), Swachchhanda Shrawan Poudel (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh141Free2019-02-22Windows: RDP Session Startup Folder Backdoor via tsclient Share Targeting Startup Path
Flags mstsc.exe activity writing to the Windows Startup folder, indicating potential RDP session backdoor placement.
Samir Bousseaden, Huntrule TeamWindowsfile_eventHigh163Free2019-02-21Windows svchost RDP via Reverse SSH Loopback Tunnel to 127.0.0.0/8:3389
Flags svchost.exe opening RDP (TCP 3389) connections to loopback, consistent with tunneled reverse access behavior.
Samir Bousseaden, Huntrule TeamWindowsnetwork_connectionHigh2410Free2019-02-16Windows WFP Event 5156: RDP traffic via loopback when hosted by svchost termsvcs
Flags Windows EventID 5156 where svchost RDP (3389) traffic targets loopback addresses, suggesting tunneled local RDP usage.
Samir Bousseaden, Huntrule TeamWindowssecurityHigh143Free2019-02-16Windows: Alert on suspicious parent process spawning csc.exe
Flags csc.exe execution when spawned by script/document hosts or PowerShell using encoded content, excluding common benign parent contexts.
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh494Free2019-02-11Windows PowerShell Script Block Matches Common Reflection and Injection Keywords
Alerts on PowerShell script block text containing reflection, dynamic assembly loading, and injection-related keywords.
Florian Roth (Nextron Systems), Perez Diego (@darkquassar), Tuan Le (NCSGroup), Huntrule TeamWindowsps_scriptMedium73Free2019-02-11