Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows: wbadmin.exe Used to Recover/Dump Sensitive Registry Hives and NTDS.dit
Alert on wbadmin.exe recovery commands targeting SAM/SECURITY/SYSTEM hives and NTDS.dit.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh100Free2024-05-10Windows Process: File Recovery from Backup via wbadmin.exe
Flags wbadmin.exe executions that perform file recovery from backups based on recoveryTarget and itemtype:File arguments.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium120Free2024-05-10Windows Process Creation: wbadmin.exe Triggered for Backup of Sensitive Registry and NTDS Files
Alerts on wbadmin.exe backup commands that reference SAM/SECURITY/SYSTEM hives or NTDS.DIT.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationHigh288Free2024-05-10Windows Firewall Allow Rule Added via WmiPrvSE.exe
Flags Windows firewall allow-rule additions where WmiPrvSE.exe is the modifying application.
frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfirewall-asMedium442Free2024-05-10Windows: Alert on Outbound Connections Initiated by dialer.exe (Microsoft Phone Dialer)
Alerts on outbound connections started by Windows dialer.exe, excluding common local and reserved IP ranges.
CertainlyP, Huntrule TeamWindowsnetwork_connectionHigh120Free2024-04-26Windows Process Creation: SoftPerfect netscan.exe Network Scanner Execution
Alerts on execution of SoftPerfect Network Scanner (netscan.exe), a potential network reconnaissance tool.
"@d4ns4n_ (Wuerth-Phoenix), Huntrule Team"Windowsprocess_creationMedium227Free2024-04-25Windows RegAsm.exe Initiates Network Connection to Public IP
Alerts on RegAsm.exe initiating outbound connections to public (non-local/private) IP addresses.
frack113, Huntrule TeamWindowsnetwork_connectionMedium120Free2024-04-25Windows DLL side-loading: KeyScramblerIE.DLL loaded by KeyScrambler.exe
Alerts on KeyScrambler.exe loading KeyScramblerIE.dll, a common DLL side-loading pattern that may indicate malicious library execution.
Swachchhanda Shrawan Poudel, Huntrule TeamWindowsimage_loadHigh529Free2024-04-15Windows Registry: MaxMpxCt Value Changed (LanmanServer Parameters)
Monitors Windows registry updates to MaxMpxCt under LanmanServer parameters, impacting SMB connection request handling.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setLow142Free2024-03-19Windows Execution of Renamed NirCmd.exe (nircmd.exe/nircmdc.exe) via PE OriginalFileName
Alerts when a process uses NirCmd.exe PE metadata while the executable name is renamed to nircmd.exe or nircmdc.exe.
X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh173Free2024-03-11Windows TeamViewer Remote Session Process Command Line Start
Flags TeamViewer_Desktop.exe being launched by TeamViewer_Service.exe with the expected IPCport and module parameters on Windows.
Josh Nickels, Qi Nan, Huntrule TeamWindowsprocess_creationLow362Free2024-03-11Windows File Creation of CrackMapExec-Related Temp Scripts and Output Files
Flags Windows file creation in C:\Windows\Temp\ with filenames and patterns associated with CrackMapExec artifacts.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsfile_eventHigh465Free2024-03-11Windows Kerberos KDC Key Distribution Failure: No Suitable Encryption Key or Unsupported EType
Flags KDC TGS generation failures where no suitable encryption key intersects or the requested encryption type is unsupported.
"@SerkinValery, Huntrule Team"WindowssystemLow101Free2024-03-07Windows AD CS Denied Certificate Enrollment Requests (Event ID 53)
Alerts on CA-side denied certificate enrollment attempts in Windows via Microsoft-Windows-CertificationAuthority Event ID 53.
"@SerkinValery, Huntrule Team"WindowssystemLow364Free2024-03-07Windows Registry: SentinelOne Scan Context Menu Command Tampering by Non-SentinelOne Process
Alerts on registry modifications to SentinelOne scan context menu command entries not matching SentinelOne’s expected binary.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium102Free2024-03-06