Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,461 rules
Windows: Suspicious Qemu execution with low-memory and network-tunneling flags
Alerts on Windows Qemu command lines using low -m values plus -netdev/connect= and -nographic.
Muhammad Faisal (@faisalusuf), Hunter Juhan (@threatHNTR), Huntrule TeamWindowsprocess_creationMedium232Free2024-06-03Windows Recall Enabled by Registry: DisableAIDataAnalysis Set to 0 (Windows)
Alerts when Windows Recall is enabled by setting the DisableAIDataAnalysis policy value to 0.
Sajid Nawaz Khan, Huntrule TeamWindowsregistry_setMedium171Free2024-06-02Windows Recall Enabled by Deleting DisableAIDataAnalysis Registry Value
Flags deletion of WindowsAI\DisableAIDataAnalysis policy value indicating Windows Recall may be enabled.
Sajid Nawaz Khan, Huntrule TeamWindowsregistry_deleteMedium4610Free2024-06-02Windows Recall Enabled via reg.exe Registry Changes (Windows)
Flags reg.exe commands that delete or set DisableAIDataAnalysis to 0 under WindowsAI to enable Windows Recall.
Sajid Nawaz Khan, Huntrule TeamWindowsprocess_creationMedium222Free2024-06-02Windows Executable Connects to portmap.io Domain Over Network
Alerts when a Windows process initiates a connection to a .portmap.io destination hostname.
Florian Roth (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium142Free2024-05-31Suspicious Web Browser Launch from PDF/Office Reader on Windows over HTTP(S)
Alerts when Acrobat/Office/PDF readers launch common browsers with HTTP(S) URLs, excluding known Microsoft and Foxit redirect patterns.
Joseph Kamau, Huntrule TeamWindowsprocess_creationMedium395Free2024-05-27Windows Process Access to Uncommon Target Images Using PROCESS_ALL_ACCESS
Alerts on Windows events granting PROCESS_ALL_ACCESS to processes with uncommon target image filenames.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_accessLow514Free2024-05-27Windows Network Connections to Cloudflared Tunnel Domains
Alerts when a Windows process initiates outbound connections to Cloudflared tunnel domain hostnames.
Kamran Saifullah, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsnetwork_connectionMedium446Free2024-05-27Windows: File Creation by mysqld.exe With Script/Executable Extensions
Alerts on file creation by mysqld.exe producing .bat/.exe/.ps1/.vbs and other executable or script file types on Windows.
Joseph Kamau, Huntrule TeamWindowsfile_eventHigh223Free2024-05-27Suspicious Child Process of KeyScrambler.exe on Windows
Alerts on KeyScrambler.exe launching cmd.exe, PowerShell, script hosts, regsvr32, or rundll32 as child processes.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsprocess_creationMedium130Free2024-05-13PowerShell Start-NetEventSession Script Block Execution Indicating Potential Network Capture (Windows)
Alerts when PowerShell ScriptBlocks reference Start-NetEventSession, indicating potential network packet or event capture.
frack113, Huntrule TeamWindowsps_scriptMedium131Free2024-05-12Windows Registry: UAC PromptOnSecureDesktop Disabled
Detects setting UAC PromptOnSecureDesktop to 0 via Windows registry policy, disabling secure desktop for UAC prompts.
frack113, Huntrule TeamWindowsregistry_setMedium182Free2024-05-10Windows Registry: UAC notification disabled via UACDisableNotify set to DWORD 0x00000001
Alerts on registry changes that disable UAC notifications by setting UACDisableNotify to 0x00000001 on Windows.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium181Free2024-05-10Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh100Free2024-05-10Windows Process: File Recovery from Backup via wbadmin.exe
Flags wbadmin.exe executions that perform file recovery from backups based on recoveryTarget and itemtype:File arguments.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium120Free2024-05-10