Sigma detection rules, expert-reviewed
Each one is checked against the reporting it came from before it is published, and shows the ATT&CK technique it covers, the telemetry it needs and where it falls short.
4,463 rules
Windows EDRSilencer Execution via Filtering Platform FilterName Change
Detects Filtering Platform custom outbound filter additions associated with potential EDRSilencer execution on Windows.
Thodoris Polyzos (@SmoothDeploy), Huntrule TeamWindowssecurityHigh438Free2024-01-29Windows Process Creation: SOAPHound Execution via AD Data Collection Command-Line Arguments
Flags SOAPHound execution on Windows by detecting command-line arguments used for Active Directory data collection.
"@kostastsale, Huntrule Team"Windowsprocess_creationHigh379Free2024-01-26Uncommon ADWS (Port 9389) Connections from Non-Standard Windows Binaries
Alerts on unexpected process-to-ADWS (TCP/9389) connections on Windows to highlight potential directory discovery.
"@kostastsale, Huntrule Team"Windowsnetwork_connectionMedium111Free2024-01-26Windows Code Page Change via mode.com Selecting Russian Code Pages
Alerts when mode.com is used to set console code pages to Russian values (1251 or 866).
Joseliyo Sanchez, @Joseliyo_Jstnk, Huntrule TeamWindowsprocess_creationMedium262Free2024-01-17Windows: Detect renamed PingCastle binary execution via PE metadata and scanner command-line
Flags Windows processes that look like renamed PingCastle executables using PE original file names and PingCastle scanner/healthcheck arguments.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh249Free2024-01-11Windows PingCastle Execution From Suspicious Parent Processes
Alerts on PingCastle (PingCastle.exe) being run with full scan/healthcheck arguments from potentially suspicious parent process locations.
Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems), Huntrule TeamWindowsprocess_creationHigh171Free2024-01-11Windows Process Creation: PingCastle Execution with Full Healthcheck Scanners
Alerts on Windows execution of PingCastle with full healthcheck and AD/security scanner command-line options.
Nasreddine Bencherchali (Nextron Systems), frack113, Huntrule TeamWindowsprocess_creationMedium152Free2024-01-11Windows .cpl Image Loads from Uncommon Paths Indicating Control Panel Abuse
Alerts on Windows loading of .cpl control panel items from uncommon paths instead of standard system directories.
Anish Bogati, Huntrule TeamWindowsimage_loadHigh294Free2024-01-09Windows WFP 5157: Connection Blocked for EDR Agent Binaries
Flags WFP blocked connections (EventID 5157) when an EDR/security agent binary is the blocked application.
"@gott_cyber, Huntrule Team"WindowssecurityHigh263Free2024-01-08Windows forfiles.exe Spawned cmd.exe from Non-System Location
Alerts on forfiles.exe running outside system paths and spawning cmd.exe with a forfiles-encoded command pattern.
Nasreddine Bencherchali (Nextron Systems), Anish Bogati, Huntrule TeamWindowsprocess_creationHigh448Free2024-01-05Windows Security: Detect NoFilter Tool Activity via RonPolicy Filtering Policy Indicators
Alerts on Windows Filtering Platform policy change events containing "RonPolicy" consistent with NoFilter abuse.
Stamatis Chatzimangou (st0pp3r), Huntrule TeamWindowssecurityHigh201Free2024-01-05Windows Process Creation: EDRSilencer Executed
Flags execution of EDRSilencer.exe on Windows based on process image and identifying metadata.
"@gott_cyber, Huntrule Team"Windowsprocess_creationHigh447Free2024-01-02Windows Process Execution of dotnet-trace.exe Child via '-- collect' Arguments
Alerts on dotnet-trace.exe executions with '-- ' and 'collect' command-line arguments that may proxy child process execution.
Jimmy Bayne (@bohops), Huntrule TeamWindowsprocess_creationMedium399Free2024-01-02Windows Registry Persistence via AppCompatFlags Layers REGISTERAPPRESTART
Detects registry persistence settings that include the AppCompat layer "REGISTERAPPRESTART" on Windows.
Nasreddine Bencherchali (Nextron Systems), Huntrule TeamWindowsregistry_setMedium259Free2024-01-01Windows Registry Change to Desktop Wallpaper Policy or Settings
Detects Windows registry updates that enforce or change the desktop wallpaper and restrict user control.
Nasreddine Bencherchali (Nextron Systems), Stephen Lincoln @slincoln-aiq (AttackIQ), Huntrule TeamWindowsregistry_setMedium82Free2023-12-21